NORTHSOLUTIONS Subscribe
DE/EN
Knowledge/Security alerts
infoFix available

CVE‑2026‑57990

CVE‑2026‑57990 is an important information disclosure vulnerability affecting Microsoft Edge (Chromium‑based). It is categorized under CWE‑552, indicating that files or directories may become accessible to external parties.

STAY INFORMED ABOUT IMPORTANT CHANGES

Follow this article.

You will receive an email when, for example, an official fix is added or the status changes to “Resolved”.

Follow article

Recommended Action

Update Microsoft Edge to version 151.0.4129.59 or later. To do this, open edge://settings/help, install the update, and then restart the browser.

CVE‑2026‑57990 is an important information disclosure vulnerability affecting Microsoft Edge (Chromium‑based). It is categorized under CWE‑552, indicating that files or directories may become accessible to external parties.

Technical Highlights Impact: Information Disclosure

Severity: Important

CVSS Score: 7.4 (Base) / 6.4 (Temporal)

Attack Vector: Network

User Interaction: Required (UI:R)

Scope Change: Possible (S:C)

Affected Version: Edge 150.0.4078.99 (Chromium 150.0.7871.187), released July 24, 2026

Attack Scenario An attacker can host a specially crafted website and lure users into visiting it. Specific user gestures can trigger the autofill mechanism, potentially exposing sensitive information.

Exploitability Publicly disclosed: No

Exploited in the wild: No

Assessment: Exploitation unlikely

Official fix: Available

This vulnerability is ideal for security deep‑dives, browser hardening guides, and corporate risk assessments, as it highlights how UI‑driven behaviors can unintentionally leak confidential data.