
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66310 is an External Control of File Name or Path vulnerability (CWE-73) in Microsoft Edge for Android that allows a local, unauthorized attacker to disclose sensitive information. It affects all versions of Microsoft Edge for Android prior to 151.0.4129.59. The vulnerability was disclosed on July 31, 2026, and published to the NVD and GitHub Advisory Database on August 4, 2026. It carries a CVSS v3.1 base score of 7.1 (High) per Microsoft's advisory, and 7.7 (High) per the GitHub Advisory Database and ENISA (Microsoft MSRC, GitHub Advisory).
The vulnerability is classified as CWE-73 (External Control of File Name or Path), meaning the application allows user-supplied input to influence file system paths or file names used in internal operations without sufficient validation. On Android, this can enable a local attacker to manipulate path references within the Edge browser to access files outside the intended scope. The attack vector is local, requires low attack complexity, and no user interaction, but does require some level of local access to the device. Related attack patterns include path traversal techniques such as URL encoding, slash manipulation, and alternate encoding schemes (CAPEC-64, CAPEC-76, CAPEC-79, CAPEC-80) (Microsoft MSRC, GitHub Advisory).
Successful exploitation results in high confidentiality and high integrity impact, with no availability impact. A local attacker can leverage this vulnerability to disclose sensitive information stored on the Android device accessible to the Edge browser process, and potentially manipulate file references to affect data integrity. The scope is unchanged, meaning the impact is confined to the vulnerable component itself, but sensitive browser data such as cookies, cached credentials, or local storage files could be exposed (Microsoft MSRC, GitHub Advisory).
There is currently no evidence of in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment classifies exploitation as "none" and notes the vulnerability is not automatable. The EPSS score is approximately 0.40% (29th percentile), indicating a low near-term probability of exploitation. CVE-2026-66310 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Microsoft MSRC, GitHub Advisory).
Microsoft has released a patched version of Microsoft Edge for Android (151.0.4129.59) that addresses this vulnerability. Users should update Microsoft Edge for Android to version 151.0.4129.59 or later via the Google Play Store. No specific configuration-based workarounds have been published; upgrading to the patched version is the recommended remediation (Microsoft MSRC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."