CVE-2026-0102Patch(microsoft / edge_chromium)

MEDIUMCVSS 3.1 · LOW

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft edge_chromium systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-359

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-18); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-17: 1Mentions · 2026-02-18: 2Mentions · 2026-02-19: 2Active Exploitation · 2026-02-19: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 2Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 102-1702-1802-19
Signal classification4 categories
Patch
240.0%
Disclosure
120.0%
General
120.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-02-182
General1Patch1
2026-02-192
Active Exploitation1Patch1
Full discourse5 posts
  • kawn@kawn2020
    Patch

    #microsoftupdate #securityupdate #Edge マイクロソフトが Microsoft Edge Stable Channel (Version 145.0.3800.58) をリリース. CVE ベースで脆弱性 1 件に対処. ・CVE-2026-0102 https://x.com/kawn2020/status/2024358804444586179

    Post summary

    Microsoft Edge released version 145.0.3800.58, which addresses CVE-2026-0102. No exploit or PoC details are provided.

    1000064
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0102 Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This c… https://www.cve.org/CVERecord?id=CVE-2026-0102

    Post summary

    CVE-2026-0102 enables a malicious webpage to automatically populate autofill fields after two taps, potentially bypassing clear user consent, highlighting a risk to user input privacy.

    00010319
    56.4K followersView on X
  • kawn@kawn2020
    Active Exploitation

    #microsoftupdate #securityupdate #Edge Microsoft Edge Stable Channel (Version 145.0.3800.58) ・CVE-2026-0102 「The Chromium team reported that CVE-2026-2441 has an exploit in the wild, and this update contains a fix for it.」

    Post summary

    The tweet reports that CVE-2026-2441 is being actively exploited in the wild and that Microsoft Edge update 145.0.3800.58 includes a fix.

    0000055
    89 followersView on X
  • Deskmodder@deskmodder
    Patch

    Microsoft Edge 145.0.3800.58 korrigiert CVE-2026-2441 und CVE-2026-0102 und weitere Änderungen Ich hatte schon gar nicht mehr damit gerechnet, dass Microsoft eine Release Notes für den Edge 145.0... https://www.deskmodder.de/blog/2026/02/18/microsoft-edge-145-0-3800-58-korrigiert-cve-2026-2441-und-cve-2026-0102-und-weitere-aenderungen/

    Post summary

    Microsoft Edge 145.0.3800.58 includes patches for CVE‑2026‑2441 and CVE‑2026‑0102, as announced in the release notes.

    0000080
    94 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-0102 Autofill Data Disclosure Vulnerability in Web Browsers via Tap Interaction https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0102

    Post summary

    The text merely lists CVE‑2026‑0102 as an autofill data disclosure flaw without additional technical, exploitation, or mitigation details.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium---

Explore more