Executive brief
Microsoft 365 Copilot for iOS is an AI-powered productivity assistant used on mobile devices to help users manage documents, emails, and tasks. A security flaw in the application's access controls could allow an unauthorized person to gain higher-level permissions than they should have. If exploited, this could lead to unauthorized access to sensitive corporate data or the ability to perform actions on behalf of a legitimate user.
Technical details
An improper access control vulnerability (CWE-284) exists in Microsoft 365 Copilot for iOS versions prior to 2.111.4. The flaw allows a remote, unauthenticated attacker to elevate their privileges via the network, though the CVSS vector indicates that some level of user interaction is required. Successful exploitation could grant the attacker unauthorized access to data or administrative functions within the application context. Microsoft has addressed this issue in version 2.111.4 and later.
Affected products
- Microsoft 365 Copilot for iOS < 2.111.4
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory