Exposure of Private Information ('Privacy Violation') in Microsoft Edge - CVE-2026-58296

 

Exposure of Private Information ('Privacy Violation') in Microsoft Edge - CVE-2026-58296

Published: July 17, 2026


Vulnerability identifier: #VU138367
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58296
CWE-ID: CWE-359
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of private personal information to an unauthorized actor in Microsoft Edge for Android autofill handling when the browser processes an attacker-controlled webpage. A remote attacker can craft malicious JavaScript and cause the victim to visit a crafted webpage to disclose sensitive information.

User interaction is required: the victim must visit an attacker-controlled webpage and perform two tap gestures that cause autofill to activate.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58296

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins