Executive brief
A command injection vulnerability exists in the Copilot Chat feature within the Microsoft Edge browser. This flaw allows an unauthorized attacker to remotely access and disclose sensitive information over the network. This could lead to the exposure of private user data or internal system details without requiring any user interaction.
Technical details
A command injection vulnerability (CWE-77) exists in Microsoft Copilot Chat within the Edge browser due to improper neutralization of special elements used in a command. The vulnerability is exploitable over the network by an unauthenticated attacker (AV:N/AC:L/PR:N/UI:N). Successful exploitation allows for unauthorized information disclosure (Confidentiality: High). While the specific mechanism of the injection is not detailed in the advisory, it is classified as an exclusively hosted service vulnerability, suggesting the fix is managed by the provider.
Affected products
- Microsoft Copilot Chat (Microsoft Edge)
Timeline
- 2026-05-07: disclosed
- 2026-05-07: advisory