Authentication bypass using an alternate path or channel in Microsoft Edge - CVE-2026-57980
Published: July 20, 2026
Microsoft Edge
Detailed vulnerability description
The vulnerability allows a remote attacker to perform tampering.
The vulnerability exists due to authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) when handling attacker-controlled web content. A remote attacker can host a specially crafted website and convince a user to visit it to perform tampering.
User interaction is required, and the user must visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate.