Improper Authorization in Microsoft Edge - CVE-2026-58284
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper authorization in Microsoft Edge (Chromium-based) when processing crafted web content or files that trigger autofill interactions. A remote attacker can host a specially crafted website or provide a specially crafted file and convince a user to interact with it to execute arbitrary code.
User interaction is required, and successful exploitation requires the victim to visit attacker-controlled content and perform two tap gestures that activate autofill. The vulnerable component and the impacted component are managed by different security authorities.