Cross-site scripting in Microsoft Edge - CVE-2026-58298
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to cross-site scripting in Microsoft Edge (Chromium-based) when rendering a crafted web page. A remote attacker can host a specially crafted website and convince a user to view it to perform spoofing.
Information in the victim's browser associated with the vulnerable URL can be read by malicious JavaScript code and sent to the attacker. User interaction is required to visit the crafted website or URL.