Type Confusion in Microsoft Edge - CVE-2026-70339
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code.
The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can trick the victim into visiting a crafted webpage and performing two tap gestures to execute code.
User interaction is required for autofill to activate.