Executive brief
A security vulnerability in the Windows Push Notification service could allow an authorized user to access sensitive information they are not supposed to see. This service is responsible for delivering real-time updates and alerts from apps to the user's desktop. An attacker with existing access to the computer could exploit this to gain unauthorized insights into system or application data, potentially compromising user privacy.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Windows Push Notification service. The flaw allows a locally authenticated attacker to bypass intended access restrictions and view sensitive data handled by the notification subsystem. The attack requires local access to the target system but does not require administrative privileges or user interaction. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2016 to address this issue.
Affected products
- Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Version 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core installations
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory