HIGH 7.1

CVE-2026-58296: Microsoft Edge Android Privacy Leak Vulnerability

A privacy vulnerability in Microsoft Edge for Android can expose users' personal information to attackers over the internet. An attacker could trick a user into performing certain actions on a compromised or attacker-controlled website, potentially revealing sensitive data stored or cached within the browser. The vulnerability requires user interaction to exploit, but once triggered, it bypasses normal privacy protections.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.1 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Weaknesses (CWE)
CWE-359
Affected products
2 configuration(s)
Published / Modified
2026-07-03 / 2026-07-07

NVD description (verbatim)

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-58296 represents a private personal information disclosure vulnerability in Microsoft Edge for Android, categorized under CWE-359 (Privacy Violation). The vulnerability has a CVSS 3.1 score of 7.1 (HIGH) with a network attack vector, low attack complexity, no privilege requirements, and required user interaction. The vulnerability achieves high confidentiality impact with minor integrity impact, and no availability impact. This indicates that while an attacker cannot modify or delete data directly, they can exfiltrate sensitive information when the user interacts with an attacker-controlled resource.

Business impact

Users of Microsoft Edge on Android devices face elevated risk of personal data exposure including browsing history, cached credentials, location data, or other stored personal information. For enterprises with BYOD policies or mobile workforce deployments, this vulnerability increases the surface area for data loss and privacy incidents. Customer trust and regulatory compliance (GDPR, CCPA, etc.) may be affected if user data is compromised at scale. The HIGH severity rating reflects the ease of exploitation and the sensitive nature of data exposure.

Affected systems

Microsoft Edge for Android running vulnerable versions is the primary affected platform. The vulnerability also involves the Google Android ecosystem as Edge for Android depends on Android's underlying system libraries and APIs. Users running current or near-current versions of Edge on Android devices should be considered at risk until patches are applied. Desktop versions of Edge and Edge on other platforms are not affected.

Exploitability

The vulnerability requires user interaction; an attacker cannot silently extract data from a device. However, the attack is triggered through ordinary network-based methods (visiting a malicious website, clicking a link, or interacting with crafted content). The low attack complexity and absence of authentication requirements make exploitation straightforward once user interaction is achieved. Social engineering, malvertising, or drive-by downloads could lower the practical barrier to triggering the vulnerability.

Remediation

Users should update Microsoft Edge for Android to the latest available version from the Google Play Store or equivalent distribution channel. Check the Microsoft Edge release notes or security advisory for specific version numbers that address CVE-2026-58296. Enterprises should enforce mobile device management (MDM) policies to push Edge updates automatically and restrict use of outdated browser versions on corporate devices.

Patch guidance

Verify the exact patched version numbers against the official Microsoft Edge security advisory, as version numbers vary by release channel and region. Most users will receive patches automatically if auto-update is enabled in the Google Play Store; verify this setting is active. For managed deployments, use MDM tools (Intune, MobileIron, etc.) to deploy patches immediately. Test patches in a small cohort before full rollout to ensure compatibility with line-of-business applications.

Detection guidance

Monitor for unusual data exfiltration from mobile devices running Edge, particularly outbound network connections to unexpected domains during or after a user's browsing session. Security information and event management (SIEM) systems with mobile visibility can flag suspicious data flows. On managed devices, deploy mobile threat defense (MTD) solutions that can detect the data access patterns associated with this vulnerability. Review browser cache and history logs for evidence of exposure. Look for authentication tokens or sensitive session data in unencrypted storage.

Why prioritize this

This vulnerability merits high-priority remediation due to its HIGH severity rating, direct impact on user privacy, low exploitation complexity, and lack of active exploitation data (not yet on CISA's KEV list). The requirement for user interaction does not significantly reduce risk in real-world scenarios where users frequently click links or visit websites. Organizations with mobile workforces, BYOD programs, or strict privacy compliance obligations should prioritize patching within 2–4 weeks.

Risk score, explained

A CVSS score of 7.1 reflects a HIGH-severity vulnerability with three key factors: (1) High confidentiality impact — sensitive personal data can be disclosed; (2) Low attack complexity — no special conditions or tools are required; (3) User interaction requirement — the attack must be socially engineered or delivered through a malicious link. The network attack vector means any internet-connected device is at risk. The lack of integrity or availability impact prevents a critical rating, but the privacy damage potential justifies urgent patching.

Frequently asked questions

Can this vulnerability steal my passwords or financial information?

Yes, depending on what data the browser has cached or stored. Personal information that has been saved in Edge — such as autofill data, browsing history, site authentication tokens, or payment details — could be exposed if an attacker successfully exploits the vulnerability. Users should change passwords for sensitive accounts after updating, especially if they suspect they visited a malicious website.

Do I need to do anything if auto-update is enabled?

If Google Play Store auto-updates are enabled on your device, Edge will patch automatically. However, verify in Play Store settings that auto-update is active, and manually check Edge version after a few days to confirm the patch was applied. For enterprise users, IT should confirm deployment through MDM reporting rather than relying on automatic play store updates.

Is this vulnerability actively being exploited in the wild?

As of the latest update, this vulnerability is not yet listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting there is no confirmed public exploitation at this time. However, given its ease of exploitation, security teams should assume threat actors are aware of it and may develop exploits after patch details become public.

Why doesn't this affect Microsoft Edge on Windows, Mac, or Linux?

This vulnerability is specific to Microsoft Edge for Android and how it handles personal data on the Android platform. Desktop versions of Edge, while based on Chromium, have different memory isolation, sandboxing, and caching mechanisms that do not expose the same information disclosure path. Android's unique architecture and browser constraints created the conditions for this specific vulnerability.

This analysis is provided for informational purposes and reflects the state of public vulnerability data as of the publication date. Verify all patch version numbers and remediation guidance against the official Microsoft Edge security advisory and your vendor's release notes. No liability is assumed for decisions made based on this intelligence. Organizations should conduct their own risk assessment and testing before deploying patches in production environments. Exploit code and detailed attack vectors are intentionally omitted; consult threat intelligence platforms for active exploitation indicators. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).