Description
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-26
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An origin validation error in Microsoft Edge (Chromium-based) allows an attacker who can send crafted network requests to read data that should be protected. The vulnerability leaks information over a communication channel, giving an unauthorized entity access to sensitive content. The flaw is classified as an information disclosure that could expose confidential data or content to the attacker.

Affected Systems

The affected product is Microsoft Edge (Chromium-based). No specific version numbers are listed, so all builds released before Microsoft’s fix may be vulnerable. Users should verify that their browser receives the latest Microsoft updates that address this issue.

Risk and Exploitability

The CVSS score of 7.4 indicates a significant risk. The EPSS score of < 1% signals a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw can be triggered remotely through network traffic, meaning any host that accepts manipulated requests is potentially at risk and should monitor for anomalous traffic to Edge and apply the vendor fix as soon as it is available.

Generated by OpenCVE AI on August 3, 2026 at 18:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that contains the fix for CVE-2026-57989.
  • If the update is not yet available, prevent unsolicited cross‑origin requests to Edge by configuring firewall or proxy rules to deny or restrict traffic that could target the browser’s origin validation logic.
  • Disable or restrict browsing of untrusted or unknown sites until the patch is applied.
  • Ensure that automatic updates for the operating system and Edge are enabled so future patches are received promptly.

Generated by OpenCVE AI on August 3, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-14T17:25:56.717Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57989

cve-icon Vulnrichment

Updated: 2026-07-27T14:49:37.700Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-26T18:18:25.033

Modified: 2026-08-03T14:56:02.713

Link: CVE-2026-57989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:15:04Z

Weaknesses