Skip to main content
Vulnerability Database/CVE-2024-26196

CVE-2024-26196: Microsoft Edge Android Information Disclosure

CVE-2024-26196 is an information disclosure vulnerability in Microsoft Edge for Android that allows unauthorized access to sensitive data. This article covers the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2024-26196 Overview

CVE-2024-26196 is an information disclosure vulnerability in Microsoft Edge for Android, the Chromium-based mobile browser. The flaw allows a remote attacker to access limited confidential information from the browser when a user interacts with malicious content. Exploitation requires user interaction, such as visiting a crafted web page or clicking a specially designed link. Microsoft assigned the issue to the CWE-259 category, which covers use of hard-coded passwords, alongside a secondary NVD-CWE-noinfo classification.

Critical Impact

An attacker can trigger disclosure of limited confidential data from Microsoft Edge for Android over the network with only user interaction, no authentication, and low attack complexity.

Affected Products

  • Microsoft Edge (Chromium-based) for Android
  • Mobile Edge browser installations distributed through the Google Play Store
  • Edge builds predating the Microsoft security update referenced in the advisory

Discovery Timeline

  • 2024-03-21 - CVE-2024-26196 published to the National Vulnerability Database
  • 2026-08-10 - Last updated in NVD database

Technical Details for CVE-2024-26196

Vulnerability Analysis

The vulnerability affects the Android build of Microsoft Edge and results in unauthorized exposure of limited confidential information. Microsoft classifies the issue as an information disclosure flaw reachable over the network. Exploitation requires the victim to perform an action, such as loading a page or following a crafted link controlled by the attacker. The confidentiality impact is limited in scope, and the vulnerability does not enable modification of data or disruption of browser availability.

The CWE-259 mapping points to use of a hard-coded credential inside the affected component. Microsoft has not published implementation details, and no proof-of-concept exploit is publicly available. The Exploit Prediction Scoring System places this issue in the 67th percentile, indicating moderate predicted exploitation likelihood relative to other CVEs.

Root Cause

According to the Microsoft Security Update Guide, the vulnerability stems from a defect in the Android build of Microsoft Edge that permits an unauthorized actor to read confidential browser data. The CWE-259 classification suggests a hard-coded secret is embedded in the mobile application, weakening the isolation between attacker-controlled web content and privileged browser context.

Attack Vector

The attack is network-based and requires user interaction. A remote attacker hosts crafted web content and lures the victim into loading it inside Microsoft Edge on Android. Successful exploitation returns limited confidential information to the attacker. No prior authentication, elevated privileges, or local access to the device are required.

No verified public exploit code is available. The vulnerability mechanism is described in prose based on the vendor advisory; see the Microsoft Security Update Guide for authoritative details.

Detection Methods for CVE-2024-26196

Indicators of Compromise

  • Outbound requests from Microsoft Edge for Android to unfamiliar hosts immediately after visiting an untrusted link.
  • Repeated redirects or short-lived pages loaded in Edge that request unexpected browser resources.
  • Presence of outdated Microsoft Edge versions on managed Android endpoints that predate the March 2024 update.

Detection Strategies

  • Inventory managed Android devices with mobile device management (MDM) tooling to identify Microsoft Edge builds below the patched release.
  • Correlate mobile web proxy logs for suspicious URL patterns delivered to Edge users on Android.
  • Alert on installations of Microsoft Edge from sources other than the Google Play Store to reduce exposure to modified builds.

Monitoring Recommendations

  • Track Edge version telemetry from MDM and enterprise browser reporting to confirm patch adoption.
  • Monitor DNS and TLS SNI logs from mobile fleets for connections to newly registered domains loaded through Edge.
  • Review Microsoft Defender for Endpoint mobile alerts related to browser exploitation attempts on Android.

How to Mitigate CVE-2024-26196

Immediate Actions Required

  • Update Microsoft Edge for Android to the latest version available through the Google Play Store on all managed and personal devices.
  • Enforce automatic browser updates through MDM policies covering Android endpoints that access corporate resources.
  • Instruct users to avoid loading untrusted links inside Edge on Android until updates are confirmed installed.

Patch Information

Microsoft addressed the issue in the update referenced in the Microsoft Security Update Guide. Administrators should confirm that Edge on Android reports a version equal to or later than the fixed build listed in the advisory.

Workarounds

  • Restrict use of Microsoft Edge for Android on corporate devices until the patched version is deployed.
  • Route mobile browser traffic through an enterprise secure web gateway that blocks known malicious domains.
  • Provide users with an alternative approved browser for handling links from untrusted sources during the patch window.
bash
# Configuration example: verify installed Edge version on an Android device via adb
adb shell dumpsys package com.microsoft.emmx | grep versionName

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.