Files or Directories Accessible to External Parties in Microsoft Edge - CVE-2026-57990

 

Files or Directories Accessible to External Parties in Microsoft Edge - CVE-2026-57990

Published: July 24, 2026 / Updated: July 25, 2026


Vulnerability identifier: #VU139359
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57990
CWE-ID: CWE-552
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to files or directories accessible to external parties in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website and convince a user to visit it to disclose sensitive information.

User interaction is required, and the user must visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate. Successful exploitation can affect resources beyond the security scope of the vulnerable component.


Affected software

Microsoft Edge

How to mitigate CVE-2026-57990

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.99

External References

Related Security Bulletins