Insufficient UI Warning of Dangerous Operations in Microsoft Edge - CVE-2026-58597

 

Insufficient UI Warning of Dangerous Operations in Microsoft Edge - CVE-2026-58597

Published: July 17, 2026


Vulnerability identifier: #VU138372
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58597
CWE-ID: CWE-357
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) when rendering an attacker-controlled webpage and activating autofill through user interaction. A remote attacker can trick the victim into visiting a crafted webpage and performing two tap gestures to perform spoofing.

Malicious JavaScript code may read information in the victim's browser associated with the vulnerable URL and send it to the attacker. User interaction is required to visit the attacker-controlled webpage and trigger autofill.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58597

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins