CVE-2026-66318

Microsoft · Microsoft Edge (Chromium-based)

An origin validation error in Microsoft Edge allows an unauthenticated attacker to disclose sensitive information over a network.

Executive summary

An origin validation error in Microsoft Edge (Chromium-based) exposes users to unauthorized information disclosure, requiring immediate browser updates.

Vulnerability

This vulnerability (CWE-346) involves an origin validation error that allows an unauthenticated attacker to bypass security checks. This facilitates the unauthorized disclosure of information when a user interacts with a malicious site.

Business impact

The CVSS score of 8.1 indicates a high severity risk. Information disclosure can result in the loss of sensitive data, including authentication tokens, cookies, or internal site content, which could be used to facilitate further attacks against the user or the broader corporate network.

Remediation

Immediate Action: Update Microsoft Edge to version 151.0.4129.59 or later to resolve the origin validation failure.

Proactive Monitoring: Monitor for unusual outbound traffic patterns from browser sessions that may indicate unauthorized data exfiltration.

Compensating Controls: Implement strict Content Security Policies (CSP) on internal web applications to mitigate the risk of cross-origin data access attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Security teams must treat browser vulnerabilities as high priority due to their potential to bypass perimeter defenses. Promptly updating the browser remains the most effective defense against this information disclosure threat.