Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw in how the browser validates the source of web content could allow a malicious website to access sensitive information from other websites or services you are logged into. This could lead to the theft of personal data or corporate credentials if a user visits a specially crafted malicious webpage.
Technical details
An origin validation error (CWE-346) exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.99. The vulnerability stems from improper enforcement of Same-Origin Policy (SOP) boundaries, allowing a remote attacker to bypass security checks. An attacker can exploit this by hosting a malicious website and tricking a user into visiting it. Successful exploitation enables the attacker to disclose sensitive information from other origins in the user's browser session. Microsoft has released updates to address this issue.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.99
Timeline
- 2026-07-26: advisory: Initial publication of CVE-2026-57989 by Microsoft and NVD.