Information disclosure in Microsoft Edge - CVE-2026-56646

 

Information disclosure in Microsoft Edge - CVE-2026-56646

Published: July 17, 2026


Vulnerability identifier: #VU138342
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56646
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) when processing attacker-controlled web content. A remote attacker can cause the victim to visit an attacker-controlled webpage and perform two tap gestures that activate autofill to perform spoofing.

User interaction is required to visit the webpage and perform the gestures that trigger autofill.


Affected software

Microsoft Edge

How to mitigate CVE-2026-56646

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins