External Control of File Name or Path in Microsoft Edge for Android - CVE-2026-65802

 

External Control of File Name or Path in Microsoft Edge for Android - CVE-2026-65802

Published: July 31, 2026 / Updated: August 2, 2026


Vulnerability identifier: #VU140709
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2026-65802
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to external control of file name or path in Microsoft Edge for Android when processing an attacker-controlled webpage that triggers autofill. A remote attacker can cause the victim to visit a specially crafted webpage and perform two tap gestures to disclose sensitive information.

User interaction is required to visit the attacker-controlled webpage and perform the two tap gestures that activate autofill. Successful exploitation can affect resources beyond the security scope of the vulnerable component.


Affected software

Microsoft Edge for Android

How to mitigate CVE-2026-65802

Install security update from vendor's website.

Microsoft Edge for Android - update to 151.0.4129.59

External References

Related Security Bulletins