Relative Path Traversal in Microsoft Edge - CVE-2026-58522

 

Relative Path Traversal in Microsoft Edge - CVE-2026-58522

Published: July 17, 2026


Vulnerability identifier: #VU138347
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58522
CWE-ID: CWE-23
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to relative path traversal in Microsoft Edge for Android when processing a crafted URL. A remote attacker can cause malicious JavaScript code to read information associated with the vulnerable URL and send it to the attacker to disclose sensitive information.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58522

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins