<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Autofill on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/autofill/</link><description>Recent content in Autofill on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 02:13:41 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/autofill/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-11636: Use After Free in Edge Autofill</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-edge-chromium-use-after-free-autofill-cve-2026-11636/</link><pubDate>Tue, 16 Jun 2026 02:13:41 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-edge-chromium-use-after-free-autofill-cve-2026-11636/</guid><description>CVE-2026-11636 is a use-after-free flaw in Chromium Autofill affecting Microsoft Edge. Learn the security impact and recommended actions for cloud architec</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11636">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability in Chromium&rsquo;s Autofill component has been assigned CVE-2026-11636 by Google. Microsoft Edge, being Chromium-based, is affected and has ingested the upstream fix from Chrome. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, making them potentially serious if exploited via a malicious webpage.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest stable release across your organisation&rsquo;s endpoints and virtual desktop infrastructure, including Azure Virtual Desktop environments. Verify endpoint management policies (e.g. via Intune or group policy) are enforcing automatic browser updates without delay.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11636">Chromium: CVE-2026-11636 Use after free in Autofill</a></p>
]]></content:encoded></item><item><title>CVE-2026-12015: Edge Chromium Autofill Use-After-Free</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-12015-microsoft-edge-chromium-autofill-use-after-free/</link><pubDate>Mon, 15 Jun 2026 14:00:35 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-12015-microsoft-edge-chromium-autofill-use-after-free/</guid><description>CVE-2026-12015 is a use-after-free flaw in Chromium&amp;#39;s Autofill component affecting Microsoft Edge. Learn the security impact and recommended actions.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-12015">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability (CVE-2026-12015) has been identified in the Autofill component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Microsoft Edge inherits this vulnerability from Chromium and is addressed via Google&rsquo;s upstream patch.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest stable release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop and Windows 365 deployments. Validate that your browser update policies via Intune or Group Policy are enforcing timely Chromium-based Edge updates, particularly for privileged users accessing cloud management consoles.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-12015">Chromium: CVE-2026-12015 Use after free  Autofill</a></p>
]]></content:encoded></item></channel></rss>