CVE-2026-0102
vulnerability analysis and mitigation

Overview

CVE-2026-0102 is an autofill data exposure vulnerability in Microsoft Edge (Chromium-based) classified as a "Defense in Depth" issue. Under specific conditions, a malicious webpage can trigger autofill population after two consecutive user taps, potentially without clear or intentional user consent, resulting in disclosure of stored autofill data such as addresses, email addresses, or phone number metadata. The vulnerability affects Microsoft Edge Chromium versions prior to 145.0.3800.58 and was published on February 17, 2026, with a patch released by Microsoft on February 10, 2026. It carries a CVSS v3.1 base score of 3.1 (Low) and is classified under CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor) (MSRC Advisory, Feedly).

Technical details

The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor), where the browser's autofill mechanism can be manipulated by a malicious webpage to populate form fields without explicit user intent. The attack vector is network-based and requires user interaction — specifically two consecutive taps on a webpage — making it a UI redressing or interaction-hijacking scenario where the attacker crafts page elements to coincide with autofill trigger conditions. Attack complexity is rated High, as the attacker must engineer specific page conditions to reliably trigger the unintended autofill behavior. No public proof-of-concept code has been identified (MSRC Advisory, Feedly).

Impact

Successful exploitation results in the unauthorized disclosure of personal information stored in the browser's autofill feature, including physical addresses, email addresses, and phone number metadata. The confidentiality impact is rated Low, with no integrity or availability impact, and the scope is unchanged — meaning the attacker cannot leverage this vulnerability to pivot beyond the browser's autofill data store. While the data exposed is limited to autofill metadata rather than passwords, it can still enable targeted phishing, identity profiling, or social engineering attacks against affected users (MSRC Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify users of Microsoft Edge Chromium versions prior to 145.0.3800.58 who have autofill data (addresses, emails, phone numbers) stored in their browser.
  2. Craft malicious webpage: Design a webpage with strategically positioned form fields or interactive elements that align with Edge's autofill trigger zones, engineered to activate autofill population upon two consecutive taps.
  3. Lure victim: Deliver the malicious URL to the target via phishing email, malicious advertisement, or compromised website redirect to induce the victim to visit the page.
  4. Trigger autofill: The victim performs two consecutive taps (e.g., on a button or link) on the malicious page, inadvertently triggering Edge's autofill to populate hidden or visible form fields with stored personal data.
  5. Exfiltrate data: JavaScript on the malicious page reads the autofill-populated field values and transmits them to an attacker-controlled server, harvesting the victim's address, email, or phone number metadata (MSRC Advisory, Feedly).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS POST requests from the browser to unexpected or unknown domains immediately following form interaction on an unfamiliar webpage; exfiltration of form field data to third-party endpoints not associated with the visited site.
  • Logs: Browser telemetry or proxy logs showing autofill events triggered on pages that do not contain legitimate login or address forms; repeated visits to suspicious domains with short session durations.
  • Process/Browser Behavior: Autofill populating fields on pages where no form submission was intentionally initiated by the user; unexpected form field population on pages with hidden or off-screen input elements.

Mitigation and workarounds

Microsoft released a patch in Microsoft Edge Chromium version 145.0.3800.58, and all users should update to this version or later immediately. As a temporary workaround, users can disable the autofill feature in Edge settings (Settings > Passwords > Offer to save passwords / Personal info) to prevent autofill data from being populated on webpages. Organizations should enforce browser update policies via group policy or Microsoft Intune to ensure timely patching, and consider implementing browser security policies to restrict navigation to known malicious or untrusted sites (MSRC Advisory, Feedly).

Community reactions

Coverage of CVE-2026-0102 has been relatively limited given its low CVSS score and "Defense in Depth" classification. Technology news outlets such as Neowin and WinBuzzer covered the Edge 145 release that included this fix, primarily focusing on new features rather than the security issue itself. Community discussion on Windows Forum noted the "Defense in Depth" designation, which Microsoft uses to indicate improvements that reduce attack surface even without a directly exploitable vulnerability in isolation. No significant researcher commentary or threat actor attribution has been observed (Neowin, Windows Forum).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management