Executive brief
A security vulnerability exists in the Windows Push Notifications service, which handles app alerts and updates. An authorized user on a system could exploit this flaw to access sensitive information that should otherwise be protected. This could lead to the exposure of private data or system details to unauthorized individuals already logged into the machine.
Technical details
This vulnerability is classified as an information disclosure (CWE-200) resulting from the use of an uninitialized resource within the Windows Push Notifications component. An attacker with local access and low privileges can exploit this flaw without any user interaction. By triggering the vulnerability, the attacker can read sensitive data from memory that was not properly cleared or initialized. Microsoft has addressed this issue in their June 2026 security updates.
Affected products
- Microsoft Windows Push Notifications
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory