CVE-2026-0102: Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Other sources
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0102?
The severity of CVE-2026-0102 is classified as medium, indicating a moderately exploitable vulnerability.
How do I fix CVE-2026-0102?
To fix CVE-2026-0102, users should update Microsoft Edge (Chromium-based) to the latest version beyond 145.0.3800.58.
Which versions of Microsoft Edge are affected by CVE-2026-0102?
CVE-2026-0102 affects Microsoft Edge versions up to and including 145.0.3800.58.
What type of vulnerability is CVE-2026-0102?
CVE-2026-0102 is a Defense in Depth vulnerability that can lead to unauthorized autofill of information.
Are all users of Microsoft Edge at risk from CVE-2026-0102?
Not all users are at risk, only those using affected versions of Microsoft Edge (Chromium-based) up to 145.0.3800.58.