Junglewise Threat Intelligence

CVE-2026-66318: Microsoft Edge origin validation error allows information disclosure

CVE-2026-66318 · Severity: high · CVSS 8.1 · Published 2026-08-04

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions to access the internet and cloud services. An origin validation flaw allows an attacker to bypass security boundaries and access sensitive information that should be restricted, potentially exposing user data or credentials without authorization.

Technical details

An origin validation error in Microsoft Edge (Chromium-based) allows an attacker to bypass the same-origin policy, a critical security boundary that prevents untrusted websites from accessing data from other origins. The vulnerability can be exploited over the network without authentication or special privileges. An attacker can craft a malicious website or use other delivery mechanisms to trigger the flaw and disclose sensitive information from the victim's browser context, such as session tokens, CSRF tokens, or other protected data. Microsoft has issued security updates to address this vulnerability.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats