Exposure of Private Information ('Privacy Violation') in Microsoft Edge - CVE-2026-58296
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of private personal information to an unauthorized actor in Microsoft Edge for Android autofill handling when the browser processes an attacker-controlled webpage. A remote attacker can craft malicious JavaScript and cause the victim to visit a crafted webpage to disclose sensitive information.
User interaction is required: the victim must visit an attacker-controlled webpage and perform two tap gestures that cause autofill to activate.