CVE-2026-66310
Microsoft · Microsoft Edge for Android
Microsoft Edge for Android contains a vulnerability involving external control of file paths, which may allow an unauthenticated attacker to perform local information disclosure.
Executive summary
A high-severity local file path manipulation vulnerability in Microsoft Edge for Android exposes users to potential local information disclosure.
Vulnerability
The software is affected by an improper control of file name or path (CWE-73), allowing an unauthenticated attacker to influence file system operations and disclose sensitive local information.
Business impact
Successful exploitation allows an attacker to bypass intended file access restrictions, potentially leading to the unauthorized disclosure of sensitive local data stored on the mobile device. With a CVSS score of 7.7, this vulnerability poses a significant risk to data confidentiality and privacy for enterprise users accessing internal resources via mobile devices.
Remediation
Immediate Action: Update Microsoft Edge for Android to version 151.0.4129.59 or later via the Google Play Store.
Proactive Monitoring: Monitor mobile device management (MDM) logs for unusual application behavior or unauthorized file access attempts originating from the browser.
Compensating Controls: Ensure that mobile devices are managed by a secure MDM policy and restrict unnecessary application permissions to limit the potential impact of file system access vulnerabilities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for unauthorized data access, all administrators should prioritize the deployment of the latest Microsoft Edge updates across their mobile fleet. Prompt patching is essential to prevent potential exploitation of this local file path vulnerability.