Executive brief
Microsoft Edge for Android is a mobile web browser used to access the internet and corporate web applications. A security vulnerability has been identified that could allow an unauthorized person to access a user's private personal information over the network. This could lead to the exposure of sensitive user data if a victim is tricked into interacting with a malicious website or link.
Technical details
An information disclosure vulnerability exists in Microsoft Edge (Chromium-based) for Android, classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). The flaw allows a remote, unauthenticated attacker to disclose sensitive information over a network, provided they can induce a user to perform a specific action (User Interaction required). The vulnerability stems from improper handling of private data within the mobile browser environment. Microsoft has addressed this in versions 150.0.4078.48 and later. The CVSS vector indicates a high impact on confidentiality and a low impact on integrity.
Affected products
- Microsoft Edge (Chromium-based) for Android 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication of CVE-2026-58297 by Microsoft and NVD.