Cross-site scripting in Microsoft Edge - CVE-2026-57977
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to cross-site scripting in Microsoft Edge (Chromium-based) when generating web pages. A remote attacker can host a specially crafted website and convince a user to visit it to perform spoofing.
User interaction is required. The user must visit an attacker-controlled webpage and perform two tap gestures that cause autofill to activate.