Type Confusion in Microsoft Edge - CVE-2026-58283

 

Type Confusion in Microsoft Edge - CVE-2026-58283

Published: July 17, 2026


Vulnerability identifier: #VU138344
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58283
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering a specially crafted website. A remote attacker can host crafted web content and convince a user to view it to perform spoofing.

Exploitation requires crafting deceptive or invisible form elements and successful user interaction involving two sequential taps. Malicious JavaScript may also read information in the victim's browser associated with the vulnerable URL.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58283

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins