Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-068