Type Confusion in Microsoft Edge - CVE-2026-58283
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering a specially crafted website. A remote attacker can host crafted web content and convince a user to view it to perform spoofing.
Exploitation requires crafting deceptive or invisible form elements and successful user interaction involving two sequential taps. Malicious JavaScript may also read information in the victim's browser associated with the vulnerable URL.