CVE-2026-58296Important
Microsoft Edge for Android Information Disclosure Vulnerability
Assessment
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- Severity
- Important
- CVSS base score
- 7.1CVSS:3.1/
AV:N/ AC:L/ PR:N/ UI:R/ S:U/ C:H/ I:L/ A:N/ E:U/ RL:O/ RC:C - Impact
- Information Disclosure
- EPSS, next 30 days
- 0.5%Higher than 43.2% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Unlikely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Edge for Android
- Weakness
- CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
- Issued by
- Microsoft
- Published
- 3 Jul 2026 · July 2026
- Last revised
- 3 Jul 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Browser1 affected product
- Microsoft Edge (Chromium-based)