(Pwn2Own) Microsoft Edge Navigation Handling Universal Cross-Site Scripting Vulnerability

June 4th, 2026

Vulnerability Details

This vulnerability allows remote attackers to execute arbitrary cross-origin script on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of navigation. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of arbitrary script. An attacker can leverage this vulnerability to execute script in the context of a target domain.

Additional Details

Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45494

Disclosure Timeline

  • 2026-05-20 - Vulnerability reported to vendor
  • 2026-06-04 - Coordinated public release of advisory
  • 2026-06-04 - Advisory Updated

Credit

Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3)

Back to Advisories