
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0102 is an autofill data exposure vulnerability in Microsoft Edge (Chromium-based) classified as a "Defense in Depth" issue. Under specific conditions, a malicious webpage can trigger autofill population after two consecutive user taps, potentially without clear or intentional user consent, resulting in disclosure of stored autofill data such as addresses, email addresses, or phone number metadata. The vulnerability affects Microsoft Edge Chromium versions prior to 145.0.3800.58 and was published on February 17, 2026, with a patch released by Microsoft on February 10, 2026. It carries a CVSS v3.1 base score of 3.1 (Low) and is classified under CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor) (MSRC Advisory, Feedly).
The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor), where the browser's autofill mechanism can be manipulated by a malicious webpage to populate form fields without explicit user intent. The attack vector is network-based and requires user interaction — specifically two consecutive taps on a webpage — making it a UI redressing or interaction-hijacking scenario where the attacker crafts page elements to coincide with autofill trigger conditions. Attack complexity is rated High, as the attacker must engineer specific page conditions to reliably trigger the unintended autofill behavior. No public proof-of-concept code has been identified (MSRC Advisory, Feedly).
Successful exploitation results in the unauthorized disclosure of personal information stored in the browser's autofill feature, including physical addresses, email addresses, and phone number metadata. The confidentiality impact is rated Low, with no integrity or availability impact, and the scope is unchanged — meaning the attacker cannot leverage this vulnerability to pivot beyond the browser's autofill data store. While the data exposed is limited to autofill metadata rather than passwords, it can still enable targeted phishing, identity profiling, or social engineering attacks against affected users (MSRC Advisory, Feedly).
Microsoft released a patch in Microsoft Edge Chromium version 145.0.3800.58, and all users should update to this version or later immediately. As a temporary workaround, users can disable the autofill feature in Edge settings (Settings > Passwords > Offer to save passwords / Personal info) to prevent autofill data from being populated on webpages. Organizations should enforce browser update policies via group policy or Microsoft Intune to ensure timely patching, and consider implementing browser security policies to restrict navigation to known malicious or untrusted sites (MSRC Advisory, Feedly).
Coverage of CVE-2026-0102 has been relatively limited given its low CVSS score and "Defense in Depth" classification. Technology news outlets such as Neowin and WinBuzzer covered the Edge 145 release that included this fix, primarily focusing on new features rather than the security issue itself. Community discussion on Windows Forum noted the "Defense in Depth" designation, which Microsoft uses to indicate improvements that reduce attack surface even without a directly exploitable vulnerability in isolation. No significant researcher commentary or threat actor attribution has been observed (Neowin, Windows Forum).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."