Executive brief
A security vulnerability exists in the Windows Push Notification service, which is responsible for delivering app alerts and updates to users. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information they are not authorized to see. This could lead to the exposure of private data contained within notifications or system logs.
Technical details
This vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) within the Windows Push Notification component. An attacker with local access and low privileges (PR:L) can exploit this flaw without any user interaction. The root cause is a failure to properly restrict access to sensitive data handled by the notification service, potentially allowing an attacker to read information belonging to other users or the system. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory