Files or Directories Accessible to External Parties in Microsoft Edge - CVE-2026-57990
Published: July 24, 2026 / Updated: July 25, 2026
Microsoft Edge
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to files or directories accessible to external parties in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website and convince a user to visit it to disclose sensitive information.
User interaction is required, and the user must visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate. Successful exploitation can affect resources beyond the security scope of the vulnerable component.