Recommended Action
Update Microsoft Edge to version 151.0.4129.59 or later. To do this, open edge://settings/help, install the update, and then restart the browser.
CVE‑2026‑57990 is an important information disclosure vulnerability affecting Microsoft Edge (Chromium‑based). It is categorized under CWE‑552, indicating that files or directories may become accessible to external parties.
Technical Highlights Impact: Information Disclosure
Severity: Important
CVSS Score: 7.4 (Base) / 6.4 (Temporal)
Attack Vector: Network
User Interaction: Required (UI:R)
Scope Change: Possible (S:C)
Affected Version: Edge 150.0.4078.99 (Chromium 150.0.7871.187), released July 24, 2026
Attack Scenario An attacker can host a specially crafted website and lure users into visiting it. Specific user gestures can trigger the autofill mechanism, potentially exposing sensitive information.
Exploitability Publicly disclosed: No
Exploited in the wild: No
Assessment: Exploitation unlikely
Official fix: Available
This vulnerability is ideal for security deep‑dives, browser hardening guides, and corporate risk assessments, as it highlights how UI‑driven behaviors can unintentionally leak confidential data.
