MEDIUM 6.5

CVE-2026-58523: Microsoft Edge Android Access Control Bypass – CVSS 6.5

Microsoft Edge for Android contains an access control vulnerability that allows an attacker to bypass a security feature through network interaction. The vulnerability requires user interaction (such as clicking a malicious link) but does not require authentication. While an attacker cannot modify data or disrupt service, they can access confidential information the user would normally be restricted from viewing.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-284
Affected products
2 configuration(s)
Published / Modified
2026-07-03 / 2026-07-07

NVD description (verbatim)

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-58523 is classified as an improper access control flaw (CWE-284) affecting Microsoft Edge for Android. The vulnerability has a CVSS 3.1 score of 6.5 (Medium severity) with a network attack vector, low attack complexity, and no privileges required. The flaw allows unauthenticated remote attackers to circumvent a security feature via network-based vectors, resulting in high confidentiality impact while maintaining integrity and availability. The vulnerability was published on July 3, 2026, and modified on July 7, 2026.

Business impact

This vulnerability poses a moderate but material risk to organizations with Android users who rely on Microsoft Edge for secure browsing. The primary business impact is confidential data exposure—users may be deceived into visiting attacker-controlled sites where sensitive information becomes accessible despite security controls. Organizations handling regulated data (HIPAA, PCI-DSS, GDPR) should assess whether Edge is used to access protected information. The requirement for user interaction somewhat limits attack scale, but social engineering and phishing campaigns could exploit this reliably.

Affected systems

Microsoft Edge for Android is the primary affected system. The vulnerability is specific to the Chromium-based Edge browser on Google Android devices. Desktop versions of Edge and other browsers are not impacted. Users running older versions of Edge for Android are at risk until patching is completed. Android version does not appear to be a limiting factor—the vulnerability stems from Edge's access control implementation rather than underlying OS features.

Exploitability

Exploitability is moderate. An attacker cannot directly trigger the vulnerability; user interaction is required, typically through a malicious link or site visit. However, attack complexity is low—the attacker does not need special privileges, credentials, or system-level access. The network-based attack vector means exploitation can occur remotely without proximity. Social engineering, phishing, or malvertising could reliably deliver attack payloads. The vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting active exploitation in the wild has not been documented at publication, though this does not guarantee zero-day status or imminent threat.

Remediation

Organizations should prioritize deploying security updates to Microsoft Edge for Android as soon as Microsoft releases patches. End users should enable automatic updates in the Google Play Store settings to ensure timely patch installation. Until patches are available, consider organizational guidance restricting use of Edge for Android to non-sensitive browsing or recommending alternative browsers (Chrome, Firefox) for access to confidential systems. Monitor Microsoft's security advisories for patch availability and exact affected version ranges.

Patch guidance

Verify the specific patch version and release timeline against Microsoft's official security advisory, as exact version numbers were not provided in this analysis. Users should check the Microsoft Edge update history in the Google Play Store to confirm patch deployment. Once Microsoft publishes details, IT teams should prepare a staged rollout to test patches on a subset of Android devices before broad deployment. Coordinate with mobile device management (MDM) solutions if your organization uses them to enforce automatic updates or restrict unpatched Edge usage.

Detection guidance

Monitor for exploitation attempts by logging network traffic to known attacker infrastructure or suspicious domains. On Android devices, enable verbose logging where supported by your mobile security tools. Look for unusual user behavior patterns: unexpected access to sensitive sites via Edge, authentication failures followed by successful access attempts, or session anomalies. Organizations using Mobile Threat Defense (MTD) solutions should verify that detection rules for access control bypasses in Edge are enabled. Network-level detection is challenging since the attack uses normal HTTPS traffic; focus on behavioral indicators and user-reported suspicious activity.

Why prioritize this

This vulnerability merits medium priority in most patch queues. The CVSS 6.5 (Medium) rating combined with the requirement for user interaction makes it less critical than remote code execution flaws, but the high confidentiality impact and ease of attack (low complexity, no authentication required) elevate it above routine updates. Organizations handling sensitive data on Android devices or where Edge is widely deployed should prioritize this patch within 2–4 weeks. Firms in regulated industries or with strict data protection requirements may want to expedite patching to the front of their Android update cycle.

Risk score, explained

The CVSS 3.1 score of 6.5 reflects a Medium-severity vulnerability with significant but not catastrophic risk. The network attack vector and low complexity indicate broad reachability and ease of exploitation. The absence of authentication requirements lowers the barrier to attack initiation. However, mandatory user interaction reduces the likelihood of large-scale automated exploitation. The high confidentiality impact (C:H) is the primary driver of the 6.5 score, while unchanged integrity (I:N) and availability (A:N) confirm that the attacker cannot alter data or cause denial of service. This risk profile is typical of access control and information disclosure vulnerabilities affecting mobile browsers.

Frequently asked questions

Does this vulnerability affect Microsoft Edge on Windows, macOS, or Linux?

No. CVE-2026-58523 is specific to Microsoft Edge for Android. Edge on desktop and other operating systems are not affected by this access control flaw. However, organizations should still patch desktop Edge versions for other security improvements unrelated to this CVE.

What happens if a user visits a malicious website while using vulnerable Edge for Android?

If an attacker crafts a malicious site exploiting this vulnerability, a user visiting it could have restricted information or features become accessible despite normal security controls. The attacker cannot inject malware or modify the user's device through this flaw alone, but they can deceive the user into revealing or accessing confidential data.

Is this vulnerability currently being exploited in the wild?

As of the publication date, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting no documented active exploitation. However, the absence of a KEV entry does not guarantee zero risk; attackers may exploit it without public disclosure. Organizations should treat this as a credible threat and plan patching accordingly.

If our organization restricts Android device access to corporate apps only, are we protected?

Partial protection depends on your implementation. If users cannot access the open web or if corporate apps do not use Edge internally, risk is reduced. However, if users have any access to Edge or if corporate apps embed Edge components, the vulnerability remains a concern. Review your mobile app architecture and access policies to confirm Edge exposure.

This analysis is based on publicly available information and the official CVE record as of the publication date. Specific patch versions, release timelines, and Microsoft's detailed security advisory should be verified directly with Microsoft before implementation. No exploit code or weaponized proof-of-concept details are provided or endorsed. Organizations should consult their security team, mobile device management vendor, and legal/compliance teams when assessing risk and deploying patches. SEC.co makes no warranty regarding the completeness or currency of this analysis. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).