Junglewise Threat Intelligence

CVE-2026-47644: Microsoft Edge Copilot Chat injection information disclosure

CVE-2026-47644 · Severity: medium · CVSS 6.5 · Published 2026-06-04

Technologies: Microsoft Edge. Vendors: Microsoft.

Executive brief

A vulnerability in the Copilot Chat feature within Microsoft Edge could allow an unauthorized attacker to access sensitive information. This occurs when the AI assistant fails to properly sanitize data before passing it to other system components. An attacker could exploit this over the network, potentially leading to the unauthorized disclosure of user data or internal system information.

Technical details

An injection vulnerability (CWE-74) exists in Microsoft Edge's Copilot Chat due to improper neutralization of special elements in output used by downstream components. An unauthenticated attacker can exploit this flaw over the network, though user interaction is required (UI:R). Successful exploitation allows the attacker to bypass security boundaries and disclose sensitive information. The vulnerability is rated with a CVSS 3.1 score of 6.5, reflecting high confidentiality impact but no impact on integrity or availability.

Affected products

  • Microsoft Copilot Chat (Microsoft Edge)

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory

References

Related threats