Description
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Published: 2026-06-04
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Copilot Chat for Microsoft Edge arises from improper neutralization of special elements in output that is subsequently rendered by a downstream component, a form of injection weakness. This flaw allows an attacker lacking authorization to read data that should be protected, resulting in the disclosure of sensitive or confidential information. The weakness is classified as CWE-74, which concerns improper handling of HTML or similar markup.

Affected Systems

Microsoft’s Copilot Chat component in Microsoft Edge is impacted. All installations of this feature that have not applied the vendor’s latest update are susceptible, as no version exceptions are listed in the advisory.

Risk and Exploitability

The reported CVSS score of 6.5 indicates a moderate overall risk to confidentiality, with no component granting integrity or availability impact. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed or recorded. The likely attack path involves an attacker sending crafted input to the Copilot Chat interface over a network connection, potentially from a malicious web page or a compromised local system, which could then cause the downstream component to reveal protected data. Given the absence of a high exploitation score and the fact that the flaw is not a privilege escalation vector, the threat remains moderate but should still be addressed promptly to prevent data leakage.

Generated by OpenCVE AI on June 4, 2026 at 23:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version that includes the Copilot Chat patch release.
  • If an immediate update is unavailable, disable the Copilot Chat feature or isolate the browser from access to sensitive local resources until a fix is applied.
  • Ensure that the Copilot Chat interface does not render user‑supplied content without proper sanitization or validation before display.

Generated by OpenCVE AI on June 4, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Title Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft copilot Chat Edge
Weaknesses CWE-74
CPEs cpe:2.3:a:microsoft:copilot_chat_edge:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft copilot Chat Edge
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Copilot Chat Edge
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-04T22:00:52.404Z

Reserved: 2026-05-19T20:12:27.070Z

Link: CVE-2026-47644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:17:32.390

Modified: 2026-06-04T23:17:32.390

Link: CVE-2026-47644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T00:15:16Z

Weaknesses