Race condition in Microsoft Edge - CVE-2026-58616
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) when handling attacker-controlled web content and autofill activation. A remote user can craft deceptive or invisible form elements and convince the victim to visit a specially crafted webpage to disclose sensitive information.
User interaction is required: the victim must visit an attacker-controlled webpage and perform two sequential taps that cause autofill to activate.