Incorrect authorization in Microsoft Edge - CVE-2026-62904
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect authorization in Microsoft Edge (Chromium-based) when handling autofill activation on an attacker-controlled webpage. A remote attacker can cause the user to visit a crafted webpage and perform two tap gestures to disclose sensitive information.
User interaction is required to visit the attacker-controlled webpage and trigger autofill with two tap gestures.