SB2026080202 - Multiple vulnerabilities in Microsoft Edge



SB2026080202 - Multiple vulnerabilities in Microsoft Edge

Published: August 2, 2026

Security Bulletin ID SB2026080202
CSH Severity
High
Patch available
YES
Number of vulnerabilities 13
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 8% Medium 69% Low 23%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 13 vulnerabilities.


1) Origin validation error (CVE-ID: CVE-2026-66318)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an origin validation error in Microsoft Edge (Chromium-based) when handling authorization requests. A remote attacker can trick a user into interacting with a malicious request to disclose sensitive information.

User interaction is required to visit an attacker-controlled webpage and perform two tap gestures that activate autofill, which can cause the application to obtain an access token on the user's behalf and send it to an attacker-controlled location.


2) Type Confusion (CVE-ID: CVE-2026-66321)

CWE-ID: CWE-843 - Type confusion

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering an attacker-controlled webpage and processing autofill-related user interaction. A remote attacker can host a specially crafted webpage to execute arbitrary code.

User interaction is required: the user must visit an attacker-controlled webpage and perform two tap gestures that cause autofill to activate.


3) Buffer over-read (CVE-ID: CVE-2026-66312)

CWE-ID: CWE-126 - Buffer over-read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to buffer over-read in Microsoft Edge (Chromium-based) when processing crafted web content. A remote user can cause the application to process crafted content to execute arbitrary code.


4) Origin validation error (CVE-ID: CVE-2026-66313)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information and perform limited tampering.

The vulnerability exists due to an origin validation error in Microsoft Edge (Chromium-based) when processing origin validation checks. A remote attacker can exploit the flaw to disclose sensitive information and perform limited tampering.


5) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-66314)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to a time-of-check time-of-use race condition in Microsoft Edge (Chromium-based) autofill handling when processing an attacker-controlled webpage and autofill activation gestures. A remote attacker can cause the victim to visit a crafted webpage and perform two tap gestures to disclose sensitive information.

User interaction is required: the victim must visit the attacker-controlled webpage and perform the two tap gestures that cause autofill to activate.


6) Use-after-free (CVE-ID: CVE-2026-66315)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when processing crafted web content. A remote attacker can trick the victim into visiting an attacker-controlled webpage and performing crafted interactions to execute arbitrary code.

User interaction is required, and successful exploitation requires the user to perform two sequential taps that activate autofill.


7) Origin validation error (CVE-ID: CVE-2026-66316)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to origin validation error in Microsoft Edge (Chromium-based) when handling an attacker-controlled webpage and autofill activation gestures. A remote attacker can lure a user to visit a crafted webpage and perform two tap gestures to perform spoofing.

User interaction is required to visit the attacker-controlled webpage and perform the two tap gestures that cause autofill to activate.


8) Code Injection (CVE-ID: CVE-2026-65804)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to spoof content and disclose sensitive information.

The vulnerability exists due to improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) when rendering an attacker-controlled webpage. A remote attacker can craft a malicious webpage to spoof content and disclose sensitive information.

User interaction is required to visit the attacker-controlled webpage and perform the gestures that activate autofill, and the user may also need to click a popup displayed on the site. Successful exploitation can affect resources beyond the security scope of the vulnerable component.


9) Missing Authorization (CVE-ID: CVE-2026-66311)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in Microsoft Edge (Chromium-based) when performing local operations. A remote attacker can exploit the authorization bypass to disclose sensitive information.


10) Origin validation error (CVE-ID: CVE-2026-66317)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information and modify data.

The vulnerability exists due to origin validation error in Microsoft Edge (Chromium-based) when processing an attacker-controlled webpage that triggers autofill through two tap gestures. A remote attacker can lure the victim into visiting a crafted webpage to disclose sensitive information and modify data.

User interaction is required to visit the attacker-controlled webpage and perform the two tap gestures that cause autofill to activate.


11) Origin validation error (CVE-ID: CVE-2026-66322)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information and spoof content.

The vulnerability exists due to origin validation error in Microsoft Edge (Chromium-based) when processing an attacker-controlled webpage and autofill activation gestures. A remote attacker can craft a webpage that triggers autofill after the user performs the required gestures to disclose sensitive information and spoof content.

User interaction is required: the user must visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate.


12) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-66325)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information and modify data.

The vulnerability exists due to server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) when processing an attacker-controlled webpage that triggers autofill. A remote attacker can trick the victim into visiting a crafted webpage and performing two tap gestures to disclose sensitive information and modify data.

User interaction is required to visit the attacker-controlled webpage and perform the two tap gestures that cause autofill to activate.


13) Missing Authorization (CVE-ID: CVE-2026-66326)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute code.

The vulnerability exists due to missing authorization in Microsoft Edge (Chromium-based) autofill handling when a user visits an attacker-controlled webpage and performs two tap gestures that activate autofill. A remote attacker can host a malicious webpage to execute code.

User interaction is required for exploitation.


Remediation

Install update from vendor's website.