Cross-site scripting in Microsoft Edge - CVE-2026-58298

 

Cross-site scripting in Microsoft Edge - CVE-2026-58298

Published: July 17, 2026


Vulnerability identifier: #VU138369
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-58298
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to cross-site scripting in Microsoft Edge (Chromium-based) when rendering a crafted web page. A remote attacker can host a specially crafted website and convince a user to view it to perform spoofing.

Information in the victim's browser associated with the vulnerable URL can be read by malicious JavaScript code and sent to the attacker. User interaction is required to visit the crafted website or URL.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58298

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins