Junglewise Threat Intelligence

CVE-2026-58616: Microsoft Edge Copilot Chat race condition information disclosure

CVE-2026-58616 · Severity: medium · CVSS 4.4 · Published 2026-08-28

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Copilot Chat in Microsoft Edge contains a race condition vulnerability that allows an authorized attacker to access and disclose sensitive information over the network. This could expose confidential data handled by the chat system, potentially compromising user privacy or corporate information shared within the application.

Technical details

The vulnerability is a race condition (CWE-362) in the shared resource synchronization mechanism of Copilot Chat within Microsoft Edge. An authorized attacker can exploit improper synchronization of concurrent execution to access information that should be protected. The attack requires prior authentication and network access to the affected component. Successful exploitation allows information disclosure without requiring additional user interaction. Microsoft has published security updates to address this vulnerability.

Affected products

  • Microsoft Edge unknown

Timeline

  • 2026-08-28: disclosed

References

Related threats