Junglewise Threat Intelligence

CVE-2026-62828: Microsoft Edge for Android improper input validation tampering

CVE-2026-62828 · Severity: medium · CVSS 5.4 · Published 2026-07-28

Vendors: Microsoft.

Executive brief

Microsoft Edge for Android, a popular mobile web browser, contains a security flaw that could allow an attacker to tamper with web content. By tricking a user into visiting a malicious website or clicking a specific link, an attacker could potentially modify what the user sees or capture limited information. This could lead to phishing attacks or the unauthorized modification of data within the browser session.

Technical details

A vulnerability classified as improper input validation (CWE-20) exists in Microsoft Edge for Android. The flaw allows a remote, unauthenticated attacker to perform network-based tampering by exploiting insufficient validation of user-supplied input. Exploitation requires user interaction, typically involving the victim navigating to a specially crafted URL or malicious website. Successful exploitation could allow an attacker to compromise the integrity of the browser session or achieve partial information disclosure. Microsoft has addressed this issue in the July 2026 security updates.

Affected products

  • Microsoft Edge for Android All versions prior to July 2026 update

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats