Operation on a Resource after Expiration or Release in Microsoft Edge - CVE-2026-58291

 

Operation on a Resource after Expiration or Release in Microsoft Edge - CVE-2026-58291

Published: July 17, 2026


Vulnerability identifier: #VU138374
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58291
CWE-ID: CWE-672
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to operation on a resource after expiration or release in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website and persuade a user to visit it to disclose sensitive information.

Successful exploitation requires deceptive or invisible form elements and two sequential user taps that activate autofill. The impact may extend beyond the security scope of the vulnerable component.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58291

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins