Improper Neutralization of Parameter/Argument Delimiters in Microsoft Edge - CVE-2026-66323
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code.
The vulnerability exists due to improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) when processing attacker-controlled web content. A remote attacker can cause the victim to visit a crafted webpage and perform two tap gestures to execute code.
User interaction is required for autofill to activate.