CVE-2026-66318
Microsoft · Microsoft Edge (Chromium-based)
An origin validation error in Microsoft Edge allows an unauthenticated attacker to disclose sensitive information over a network.
Executive summary
An origin validation error in Microsoft Edge (Chromium-based) exposes users to unauthorized information disclosure, requiring immediate browser updates.
Vulnerability
This vulnerability (CWE-346) involves an origin validation error that allows an unauthenticated attacker to bypass security checks. This facilitates the unauthorized disclosure of information when a user interacts with a malicious site.
Business impact
The CVSS score of 8.1 indicates a high severity risk. Information disclosure can result in the loss of sensitive data, including authentication tokens, cookies, or internal site content, which could be used to facilitate further attacks against the user or the broader corporate network.
Remediation
Immediate Action: Update Microsoft Edge to version 151.0.4129.59 or later to resolve the origin validation failure.
Proactive Monitoring: Monitor for unusual outbound traffic patterns from browser sessions that may indicate unauthorized data exfiltration.
Compensating Controls: Implement strict Content Security Policies (CSP) on internal web applications to mitigate the risk of cross-origin data access attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Security teams must treat browser vulnerabilities as high priority due to their potential to bypass perimeter defenses. Promptly updating the browser remains the most effective defense against this information disclosure threat.