Type Confusion in Microsoft Edge - CVE-2026-58285
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content or opening a specially crafted file. A remote attacker can host a specially crafted website or provide a specially crafted file to execute arbitrary code.
User interaction is required, and successful exploitation requires the victim to perform two sequential taps that cause autofill to activate. A successful exploit can affect resources beyond the security scope of the vulnerable component.