Link following in Microsoft Edge - CVE-2026-57991
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) when rendering an attacker-controlled webpage. A remote attacker can host a specially crafted website and convince a user to visit it to disclose sensitive information.
User interaction is required, and the user must visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate.