CVE-2026-58297
HIGHCVSS 7.1/10EPSS 0.32%
Last modified
CVE-2026-58297 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Edge Chromium | < 150.0.4078.48 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-58297?
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
How severe is CVE-2026-58297?
CVE-2026-58297 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2026-58297?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58291Operation on a resource after expiration or release in Micro…6.1
- CVE-2026-58292Improper input validation in Microsoft Edge (Chromium-based)…7.5
- CVE-2026-58293External control of file name or path in Microsoft Edge (Chr…7.5
- CVE-2026-58294Use after free in Microsoft Edge (Chromium-based) allows an …7.5
- CVE-2026-58295Access of resource using incompatible type ('type confusion'…8.3
- CVE-2026-58296Exposure of private personal information to an unauthorized …7.1
- CVE-2026-58298Improper neutralization of input during web page generation …6.1
- CVE-2026-58299Time-of-check time-of-use (toctou) race condition in Microso…7.5
- CVE-2026-5830A vulnerability was identified in Tenda AC15 15.03.05.18. Th…8.8
- CVE-2026-58300Absolute path traversal in Microsoft Edge for Android allows…6.2
- CVE-2026-58302rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows…8.4
- CVE-2026-58303Stack-based buffer overflow vulnerability in Samsung Open So…6.1
Are you affected by CVE-2026-58297?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
