(Pwn2Own) Microsoft Edge Navigation Handling Universal Cross-Site Scripting Vulnerability
Vulnerability Details
This vulnerability allows remote attackers to execute arbitrary cross-origin script on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of navigation. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of arbitrary script. An attacker can leverage this vulnerability to execute script in the context of a target domain.
Additional Details
Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45494
Disclosure Timeline
- 2026-05-20 - Vulnerability reported to vendor
- 2026-06-04 - Coordinated public release of advisory
- 2026-06-04 - Advisory Updated
Credit
Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3)