Insufficient UI Warning of Dangerous Operations in Microsoft Edge - CVE-2026-58597
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) when rendering an attacker-controlled webpage and activating autofill through user interaction. A remote attacker can trick the victim into visiting a crafted webpage and performing two tap gestures to perform spoofing.
Malicious JavaScript code may read information in the victim's browser associated with the vulnerable URL and send it to the attacker. User interaction is required to visit the attacker-controlled webpage and trigger autofill.