Junglewise Threat Intelligence

CVE-2026-58522: Microsoft Edge for Android relative path traversal

CVE-2026-58522 · Severity: medium · CVSS 6.8 · Published 2026-07-03

Technologies: Microsoft Edge, Microsoft Edge (Chromium-based) for Android. Vendors: Microsoft.

Executive brief

Microsoft Edge for Android is a mobile web browser used for accessing internet and intranet resources. A security flaw in the application allows an unauthorized person with local access to the device to bypass file restrictions and view sensitive information. This could lead to the exposure of private user data or application configuration files stored on the mobile device.

Technical details

A relative path traversal vulnerability (CWE-23) exists in Microsoft Edge for Android. The flaw allows an attacker with local access to the device to navigate outside of intended directory restrictions by using specially crafted file paths. Successful exploitation enables the unauthorized disclosure of sensitive information from the local file system. The vulnerability is addressed in versions 150.0.4078.48 and later. No user interaction or elevated privileges are required for exploitation, though the attacker must have local access to the device.

Affected products

  • Microsoft Edge (Chromium-based) for Android >= 1.0.0.0, < 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats