Junglewise Threat Intelligence

CVE-2026-58300: Microsoft Edge for Android absolute path traversal

CVE-2026-58300 · Severity: medium · CVSS 6.2 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based) for Android, Microsoft Edge. Vendors: Microsoft.

Executive brief

A security vulnerability in the Microsoft Edge browser for Android devices could allow an unauthorized person with local access to the device to view sensitive information. This issue stems from how the application handles file paths, potentially exposing private data stored within the app's environment. Users are advised to update their browser to the latest version to mitigate this risk.

Technical details

An absolute path traversal vulnerability (CWE-36) exists in Microsoft Edge for Android versions prior to 150.0.4078.48. The flaw allows a local, unauthorized attacker to bypass intended file access restrictions by providing absolute paths to sensitive files. Successful exploitation enables the disclosure of information from the application's local storage. The attack requires local access to the device but does not require elevated privileges or user interaction. Microsoft has addressed this issue in the latest browser updates.

Affected products

  • Microsoft Edge (Chromium-based) for Android 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Microsoft published the security advisory and NVD entry.

References

Related threats