Improper Authorization in Microsoft Edge - CVE-2026-58284

 

Improper Authorization in Microsoft Edge - CVE-2026-58284

Published: July 17, 2026


Vulnerability identifier: #VU138357
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58284
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper authorization in Microsoft Edge (Chromium-based) when processing crafted web content or files that trigger autofill interactions. A remote attacker can host a specially crafted website or provide a specially crafted file and convince a user to interact with it to execute arbitrary code.

User interaction is required, and successful exploitation requires the victim to visit attacker-controlled content and perform two tap gestures that activate autofill. The vulnerable component and the impacted component are managed by different security authorities.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58284

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins