Junglewise Threat Intelligence

CVE-2026-58523: Microsoft Edge for Android improper access control security bypass

CVE-2026-58523 · Severity: medium · CVSS 6.5 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based) for Android. Vendors: Microsoft.

Executive brief

Microsoft Edge for Android contains a security flaw that allows an attacker to bypass built-in security protections. By tricking a user into visiting a malicious website or clicking a link, an attacker could gain unauthorized access to sensitive information. This could lead to the exposure of private user data or browsing history.

Technical details

An improper access control vulnerability (CWE-284) exists in Microsoft Edge (Chromium-based) for Android. The flaw allows a remote, unauthenticated attacker to bypass security features by leveraging a network-based attack vector. Exploitation requires a user to interact with a malicious link or site (UI:R). Successful exploitation could result in high confidentiality impacts, allowing the attacker to access information that should be protected by the browser's security boundaries. The issue is addressed in version 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) for Android 1.0.0.0 to 150.0.4078.47

Timeline

  • 2026-07-03: advisory: Microsoft published the security advisory.
  • 2026-07-03: patched: Fixed in version 150.0.4078.48.

References

Related threats