Improper access control in Microsoft Edge - CVE-2026-58286
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing and disclose sensitive information.
The vulnerability exists due to improper access control in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website with deceptive or invisible form elements to perform spoofing and disclose sensitive information.
Successful exploitation requires crafting deceptive or invisible form elements and the user to perform two sequential taps. Malicious JavaScript code can read information in the victim's browser associated with the vulnerable URL.