Type Confusion in Microsoft Edge - CVE-2026-58295
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website to bypass a security feature.
Successful exploitation can allow malicious JavaScript code to read information in the victim's browser associated with the vulnerable URL. User interaction is required to view the crafted content.