Improper access control in Microsoft Edge - CVE-2026-58282

 

Improper access control in Microsoft Edge - CVE-2026-58282

Published: July 17, 2026


Vulnerability identifier: #VU138343
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58282
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to improper access control in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website with deceptive or invisible form elements to perform spoofing.

User interaction is required, and successful exploitation requires the user to perform two sequential taps. Malicious JavaScript code can read information in the victim's browser associated with the vulnerable URL and send it to the attacker. The impact can extend beyond the security scope of the vulnerable component.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58282

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins