HIGH 7.1

CVE-2026-58297: Microsoft Edge Android Privacy Vulnerability – CVSS 7.1 (HIGH)

Microsoft Edge on Android contains a privacy flaw that allows attackers to access and transmit private user information over the network without authorization. The issue requires user interaction (such as visiting a malicious site) but does not require any special system access to exploit. An attacker can leverage this vulnerability to steal sensitive personal data from affected Android devices.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.1 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Weaknesses (CWE)
CWE-359
Affected products
2 configuration(s)
Published / Modified
2026-07-03 / 2026-07-07

NVD description (verbatim)

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-58297 is an information disclosure vulnerability in Microsoft Edge for Android (Chromium-based) that stems from improper handling of private personal information. The vulnerability is classified under CWE-359 (Privacy Violation) and has a CVSS 3.1 score of 7.1 (HIGH severity). The attack vector is network-based with low complexity and does not require privileges, but does require user interaction. The impact is high confidentiality loss with minor integrity exposure, while availability is not affected.

Business impact

For organizations deploying Microsoft Edge on Android devices—particularly in bring-your-own-device (BYOD) or corporate mobile programs—this vulnerability poses a risk of employee personal data leakage. Affected users could have sensitive information (contacts, browsing history, authentication tokens, or application data) intercepted or stolen by network-based attackers. In regulated industries, such data exposure may trigger compliance reporting obligations and breach notification requirements. The requirement for user interaction limits mass exploitation but does not eliminate risk in targeted scenarios.

Affected systems

The vulnerability affects Microsoft Edge (Chromium-based version) on Android devices. The associated Android operating system is also listed in the affected products, indicating the issue may be specific to certain Android versions or configurations. Organizations should verify which Edge versions in their environment correspond to vulnerable builds through the Microsoft security advisory.

Exploitability

Exploitation requires network-level access and user interaction—typically tricking a user into visiting a specially crafted website or clicking a malicious link. No authentication, privileges, or complex manipulation is required from the attacker perspective. The vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting no evidence of in-the-wild exploitation at the time of publication, though this does not guarantee future attack likelihood.

Remediation

Apply security updates from Microsoft as soon as they become available. Users should upgrade Microsoft Edge on Android to a patched version released after the vulnerability disclosure. Beyond patching, organizations should review mobile security policies, enforce HTTPS everywhere, and consider network-based filtering of known malicious sites. For high-risk environments, temporarily restricting Edge usage on Android until patches are validated may be prudent.

Patch guidance

Monitor Microsoft's official security advisories for Edge-specific patches addressing CVE-2026-58297. Patches will typically be rolled out through the Google Play Store and should be deployed promptly to all Android devices running Edge in your environment. Verify patch applicability against your current Edge version number (compare against the vendor advisory to confirm you are on a fixed build). Test patches in a small pilot group before full deployment to ensure compatibility with your mobile device management (MDM) solution and corporate apps.

Detection guidance

Monitor for suspicious network traffic originating from Edge on Android (look for unusual data exfiltration patterns). Check MDM logs for unpatched Edge installations and cross-reference against patch deployment records. Network-based detection is limited; focus on vulnerability scanning and asset inventory to identify vulnerable devices. Consider leveraging mobile threat defense solutions that can detect anomalous data access patterns or network exfiltration from the Edge browser.

Why prioritize this

This vulnerability merits timely but not emergency patching. The HIGH severity score reflects the significant confidentiality impact, but the requirement for user interaction and lack of active exploitation in the wild reduce immediate risk. Prioritize based on your organization's Android user base size, the sensitivity of data accessible via Edge on those devices, and your compliance obligations. In BYOD programs, prioritize communication and user-friendly patch deployment to ensure adoption.

Risk score, explained

The CVSS 7.1 (HIGH) score reflects the combination of high confidentiality impact (private information disclosed), low-complexity network attack vector, and minimal barriers to exploitation. The presence of user interaction prevents a critical rating despite the sensitive nature of the data at risk. The vulnerability does not impact system integrity or availability, further supporting the HIGH (not CRITICAL) classification.

Frequently asked questions

Does this vulnerability affect Microsoft Edge on Windows, macOS, or iOS?

CVE-2026-58297 is specific to Microsoft Edge on Android. Versions of Edge on other platforms may have different attack surfaces and are not listed as affected by this CVE. However, always verify the vendor advisory to confirm scope for all platforms in your environment.

What type of personal information is at risk?

The vulnerability exposes private personal information accessible to the Edge browser process on Android. This may include browsing history, cached credentials, contact data, and user-specific application information. The exact data at risk depends on what is stored locally and what is transmitted in response to the vulnerability trigger.

Is this vulnerability being actively exploited in the wild?

As of the publication date, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed active exploitation. However, this does not guarantee future safety; timely patching remains essential.

Can patching be delayed if we restrict Edge usage on Android?

While restricting Edge usage would lower exposure, this is a temporary containment measure, not a substitute for patching. Users often re-enable restricted apps or find workarounds. A coordinated patching strategy is more sustainable and less disruptive than prolonged app restrictions.

This analysis is provided for informational purposes and reflects the state of information as of the publication date. SEC.co does not guarantee the accuracy of vendor advisory details; organizations must verify all patch versions, affected build numbers, and remediation steps directly with Microsoft's official security bulletins. The absence of CVE status in CISA's KEV catalog does not indicate absence of real-world risk or future exploitation. Always conduct internal testing before deploying patches to production environments. This document does not constitute legal, compliance, or professional security advice; consult qualified security professionals for implementation guidance specific to your infrastructure. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).