Code Injection in Microsoft Edge - CVE-2026-65804
Published: July 31, 2026 / Updated: August 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof content and disclose sensitive information.
The vulnerability exists due to improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) when rendering an attacker-controlled webpage. A remote attacker can craft a malicious webpage to spoof content and disclose sensitive information.
User interaction is required to visit the attacker-controlled webpage and perform the gestures that activate autofill, and the user may also need to click a popup displayed on the site. Successful exploitation can affect resources beyond the security scope of the vulnerable component.