Impact
The vulnerability is an improper neutralization of special elements used in a command, allowing an unauthorized attacker to execute code over a network via Copilot Chat in Microsoft Edge. This command‑injection flaw, classified as CWE‑77, permits arbitrary code execution on the device, potentially compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Edge Copilot for Android and Microsoft Edge Copilot for iOS are affected. No specific version ranges are provided, so any released version prior to an official fix is vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. While the EPSS score is under 1 %, meaning exploitation is considered unlikely, the flaw remains a high‑risk remote code execution vulnerability. The vulnerability can be triggered over a network by sending crafted content to the application, and it is not listed in CISA’s KEV catalog, so no publicly known exploits are currently documented.
OpenCVE Enrichment