Improper access control in Microsoft Edge - CVE-2026-58282
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to improper access control in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website with deceptive or invisible form elements to perform spoofing.
User interaction is required, and successful exploitation requires the user to perform two sequential taps. Malicious JavaScript code can read information in the victim's browser associated with the vulnerable URL and send it to the attacker. The impact can extend beyond the security scope of the vulnerable component.