Advisory Details

June 4th, 2026

(Pwn2Own) Microsoft Edge Navigation Handling Universal Cross-Site Scripting Vulnerability

ZDI-26-330
ZDI-CAN-31430

CVE ID CVE-2026-45494
CVSS SCORE 5.0, AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
AFFECTED VENDORS Microsoft
AFFECTED PRODUCTS Edge
VULNERABILITY DETAILS

This vulnerability allows remote attackers to execute arbitrary cross-origin script on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of navigation. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of arbitrary script. An attacker can leverage this vulnerability to execute script in the context of a target domain.

ADDITIONAL DETAILS Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45494
DISCLOSURE TIMELINE
  • 2026-05-20 - Vulnerability reported to vendor
  • 2026-06-04 - Coordinated public release of advisory
  • 2026-06-04 - Advisory Updated
CREDIT Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3)
BACK TO ADVISORIES