CVE-2026-58300: Microsoft Edge for Android Information Disclosure Vulnerability
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Edge for Android Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.4078.48
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58300?
The severity of CVE-2026-58300 is rated as medium with a score of 6.2.
What is the risk associated with CVE-2026-58300?
CVE-2026-58300 carries a risk score of 36.
How does CVE-2026-58300 affect Microsoft Edge for Android?
CVE-2026-58300 allows an unauthorized attacker to perform absolute path traversal and potentially disclose sensitive information locally.
Is there any way to mitigate CVE-2026-58300?
To mitigate CVE-2026-58300, it is recommended to update to the latest version of Microsoft Edge for Android that contains the fix.
What types of information can be disclosed by exploiting CVE-2026-58300?
Exploiting CVE-2026-58300 could lead to the disclosure of sensitive information stored locally on the device.