Description
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in origin validation within Microsoft Edge (Chromium‑based) allows an unauthorized attacker to disclose sensitive information over a network. The vulnerability lies in how the browser verifies the origin of requests, enabling the attacker to retrieve data that should be restricted to a specific origin. The impact is pure information disclosure, with no direct compromise or execution capabilities indicated.

Affected Systems

Microsoft Edge (Chromium‑based) is the affected product. No specific affected versions are listed in the data, so all installations of this browser could be vulnerable until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 8.1 signals a high‑severity issue. Because an EPSS score is not available, the current probability of exploitation in the wild is unknown, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly documented exploits. The attack vector is inferred to be remote, leveraging crafted network traffic that bypasses the browser’s origin checks to exfiltrate data. Given the high severity and lack of other mitigations, remedial action is required urgently.

Generated by OpenCVE AI on August 4, 2026 at 09:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version that includes the fix.
  • Configure Windows Update or Microsoft Edge update settings for automatic installation of critical updates.
  • Monitor network traffic for abnormal origin header usage or unexpected data leakage patterns.

Generated by OpenCVE AI on August 4, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:00:44.642Z

Reserved: 2026-07-24T18:06:51.296Z

Link: CVE-2026-66318

cve-icon Vulnrichment

Updated: 2026-08-04T15:33:11.652Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:39.317

Modified: 2026-08-06T17:05:52.130

Link: CVE-2026-66318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:45:03Z

Weaknesses