Junglewise Threat Intelligence

CVE-2026-70309: Microsoft Edge origin validation error security feature bypass

CVE-2026-70309 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users to browse the internet and access online services. An origin validation flaw allows attackers to bypass a security feature over the network, potentially enabling unauthorized access to sensitive features or user data that should be protected by browser security controls.

Technical details

The vulnerability is an origin validation error in Microsoft Edge (Chromium-based) that allows unauthorized attackers to bypass a security feature via network attack. The issue stems from improper validation of request origins, enabling an attacker to circumvent browser security mechanisms designed to protect against cross-origin attacks. The attack is network-reachable and requires no authentication or elevated privileges. An attacker can exploit this to bypass origin-based security controls, potentially gaining unauthorized access to protected functionality or data. Patches are expected to be available through Microsoft's standard security update process.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References

Related threats