Junglewise Threat Intelligence

CVE-2026-58296: Microsoft Edge for Android information disclosure

CVE-2026-58296 · Severity: high · CVSS 7.1 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based) for Android. Vendors: Microsoft.

Executive brief

A security vulnerability in the Microsoft Edge browser for Android devices could allow an unauthorized person to access a user's private personal information. This occurs when a user interacts with a malicious website or link, potentially leading to the theft of sensitive data. Such an incident could compromise user privacy and lead to identity theft or unauthorized access to personal accounts.

Technical details

A vulnerability classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor) exists in Microsoft Edge for Android. The flaw allows a remote, unauthenticated attacker to disclose sensitive information over a network, provided they can induce a user to perform a specific action (User Interaction required). The CVSS vector indicates a high impact on confidentiality and a low impact on integrity. Microsoft has addressed this in versions starting from 150.0.4078.48.

Affected products

  • Microsoft Edge (Chromium-based) for Android 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial publication of the vulnerability by Microsoft and NVD.

References

Related threats