CVE-2026-57989
Microsoft · Edge (Chromium-based)
An origin validation error in Microsoft Edge allows an unauthenticated, remote attacker to disclose sensitive information over the network through user interaction.
Executive summary
A high-severity origin validation vulnerability in Microsoft Edge could permit unauthorized information disclosure when a user visits a malicious site.
Vulnerability
The vulnerability is categorized as a CWE-346: Origin Validation Error. It allows an attacker to bypass security checks and access information they are not authorized to view, provided the user is enticed to interact with a malicious resource.
Business impact
With a CVSS score of 7.4, this vulnerability poses a significant risk to data privacy. Successful exploitation could allow attackers to exfiltrate session data or sensitive information from internal or external resources, potentially leading to identity theft or unauthorized access to corporate applications.
Remediation
Immediate Action: Update Microsoft Edge to version 150.0.4078.99 or later immediately.
Proactive Monitoring: Review web proxy and firewall logs for unusual cross-origin traffic patterns or unexpected data transfers to external domains.
Compensating Controls: Implement browser security policies via Group Policy or MDM to restrict extensions and enforce safe browsing configurations.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should deploy the latest Microsoft Edge security updates across all endpoints. Users should be reminded to exercise caution when clicking links or navigating to untrusted websites until the update is applied.