Operation on a Resource after Expiration or Release in Microsoft Edge - CVE-2026-58291
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to operation on a resource after expiration or release in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website and persuade a user to visit it to disclose sensitive information.
Successful exploitation requires deceptive or invisible form elements and two sequential user taps that activate autofill. The impact may extend beyond the security scope of the vulnerable component.