CVE-2026-65802

edge_chromium: External Control of File Name or Path (CVE-2026-65802)

Beschreibung

Externe Kontrolle des Dateinamens oder Pfads in Microsoft Edge für Android ermöglicht es einem nicht autorisierten Angreifer, Informationen über ein Netzwerk offenzulegen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.4
Quelle: nvd-v3
41.4 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-04 00:17 UTC
CWE-73

Weakness-Klassen (CWE)

  • CWE-73Base

    External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-08-07 10:57 UTC· nvd@nist.gov
    • CPE Configuration: AND OR *cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:-:*:*:* versions up to (excluding) 151.0.4129.59 OR cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    • Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65802 Types: Vendor Advisory
  2. CVE Modified2026-08-04 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-65802","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-08-04 00:17 UTC· secure@microsoft.com
    • Affected: Microsoft Edge (Chromium-based)
    • Description: External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
    • CWE: CWE-73

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • microsoft

    edge_chromium151.0.4129.59

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-65802