Improper access control in Microsoft Edge - CVE-2026-58523
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to improper access control in Microsoft Edge for Android autofill handling when a user visits an attacker-controlled webpage and performs two tap gestures that activate autofill. A remote attacker can craft a malicious webpage to bypass a security feature.
User interaction is required to visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate.