Origin validation error in Microsoft Edge - CVE-2026-66318
Published: July 31, 2026 / Updated: August 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an origin validation error in Microsoft Edge (Chromium-based) when handling authorization requests. A remote attacker can trick a user into interacting with a malicious request to disclose sensitive information.
User interaction is required to visit an attacker-controlled webpage and perform two tap gestures that activate autofill, which can cause the application to obtain an access token on the user's behalf and send it to an attacker-controlled location.