CVE-2026-66310: Microsoft Edge for Android Information Disclosure Vulnerability
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Other sources
Microsoft Edge for Android Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.59
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66310?
CVE-2026-66310 has a severity rating of high (7.7).
How do I fix CVE-2026-66310?
To fix CVE-2026-66310, ensure that you update Microsoft Edge for Android to the latest version provided by Microsoft.
What type of vulnerability is CVE-2026-66310?
CVE-2026-66310 is an information disclosure vulnerability affecting Microsoft Edge for Android.
What could an attacker gain from exploiting CVE-2026-66310?
An attacker exploiting CVE-2026-66310 could disclose sensitive information locally on the user’s device.
Who is affected by CVE-2026-66310?
Users of Microsoft Edge for Android are affected by CVE-2026-66310.