Exposure of Private Information ('Privacy Violation') in Microsoft Edge - CVE-2026-58297

 

Exposure of Private Information ('Privacy Violation') in Microsoft Edge - CVE-2026-58297

Published: July 17, 2026


Vulnerability identifier: #VU138368
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58297
CWE-ID: CWE-359
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of private personal information to an unauthorized actor in Microsoft Edge for Android autofill handling when visiting an attacker-controlled webpage and activating autofill. A remote attacker can use malicious JavaScript on a crafted webpage to read information associated with the vulnerable URL and send it to disclose sensitive information.

User interaction is required: the user must visit an attacker-controlled webpage and perform two tap gestures that cause autofill to activate.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58297

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins