Exposure of Private Information ('Privacy Violation') in Microsoft Edge - CVE-2026-58297
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of private personal information to an unauthorized actor in Microsoft Edge for Android autofill handling when visiting an attacker-controlled webpage and activating autofill. A remote attacker can use malicious JavaScript on a crafted webpage to read information associated with the vulnerable URL and send it to disclose sensitive information.
User interaction is required: the user must visit an attacker-controlled webpage and perform two tap gestures that cause autofill to activate.