Junglewise Threat Intelligence

CVE-2026-58617: Microsoft 365 Copilot for iOS privilege escalation

CVE-2026-58617 · Severity: high · CVSS 8.1 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

Microsoft 365 Copilot for iOS is an AI-powered productivity assistant used on mobile devices to help users manage documents, emails, and tasks. A security flaw in the application's access controls could allow an unauthorized person to gain higher-level permissions than they should have. If exploited, this could lead to unauthorized access to sensitive corporate data or the ability to perform actions on behalf of a legitimate user.

Technical details

An improper access control vulnerability (CWE-284) exists in Microsoft 365 Copilot for iOS versions prior to 2.111.4. The flaw allows a remote, unauthenticated attacker to elevate their privileges via the network, though the CVSS vector indicates that some level of user interaction is required. Successful exploitation could grant the attacker unauthorized access to data or administrative functions within the application context. Microsoft has addressed this issue in version 2.111.4 and later.

Affected products

  • Microsoft 365 Copilot for iOS < 2.111.4

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References