Microsoft Edge Information Disclosure Vulnerability

Vulnerability

A vulnerability in Microsoft Edge (Chromium-based) allows unauthorized attackers to disclose sensitive information over the network. This issue arises from operations on a resource after its expiration or release.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Reproduction

To exploit this vulnerability, an attacker would need to host a specially crafted website designed to activate the autofill feature in Microsoft Edge. The attacker must then convince a user to visit the website and perform two tap gestures to trigger the vulnerability. This could be done through an email or instant message enticement, or by sending an attachment that the user opens.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Edge Release Notes - Security page.

Added: Jul 3, 2026, 9:34 PM
Updated: Jul 3, 2026, 9:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.6
remediation
7.7
relevance
8.9
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.