Junglewise Threat Intelligence

CVE-2026-48561: Microsoft Copilot command injection in mobile applications

CVE-2026-48561 · Severity: critical · CVSS 9.6 · Published 2026-07-14

Technologies: Microsoft 365 Copilot. Vendors: Microsoft.

Executive brief

Microsoft Copilot, an AI-powered productivity assistant, is affected by a critical security flaw that could allow an unauthorized attacker to execute malicious code. By tricking a user into a specific interaction, an attacker could gain full control over the application's environment, potentially leading to the theft of sensitive data or unauthorized access to corporate resources. This vulnerability impacts the mobile versions of the application on both Android and iOS devices.

Technical details

A command injection vulnerability (CWE-77) exists in Microsoft 365 Copilot for Android and iOS due to improper neutralization of special elements used in a command. The vulnerability can be exploited over the network by an unauthenticated attacker, though it requires some level of user interaction (UI:R). Successful exploitation allows for remote code execution with a 'Changed' scope (S:C), meaning the attacker can impact resources beyond the Copilot application itself. Microsoft has addressed this issue in the July 2026 security updates.

Affected products

  • Microsoft Microsoft 365 Copilot for Android versions prior to July 14, 2026 release
  • Microsoft Microsoft 365 Copilot for iOS versions prior to July 14, 2026 release

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched

References

Related threats