Information disclosure in Microsoft Edge - CVE-2026-56646
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) when processing attacker-controlled web content. A remote attacker can cause the victim to visit an attacker-controlled webpage and perform two tap gestures that activate autofill to perform spoofing.
User interaction is required to visit the webpage and perform the gestures that trigger autofill.