Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata. | |
| Title | Microsoft Edge (Chromium-based) Defense in Depth Vulnerability | |
| First Time appeared |
Microsoft
Microsoft edge Chromium |
|
| Weaknesses | CWE-359 | |
| CPEs | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft edge Chromium |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-17T22:55:43.100Z
Reserved: 2025-10-17T23:35:05.037Z
Link: CVE-2026-0102
No data.
Status : Received
Published: 2026-02-17T20:22:05.500
Modified: 2026-02-17T20:22:05.500
Link: CVE-2026-0102
No data.
OpenCVE Enrichment
No data.
Weaknesses