CVE-2026-66310: Microsoft Edge for Android Information Disclosure Vulnerability

Overview

Severity
High (CVSS 7.7)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Jul
Released
2026-07-31

Description

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

FAQ

What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 151.0.4129.59 07/31/2026 151.0.7922.71/.72 What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.

Affected Products (1)

Browser

  • Microsoft Edge for Android

Acknowledgments

Kugelblitz with Microsoft, Kugelblitz with Microsoft

Revision History

  • 2026-07-31: Information published.