Impact
The flaw is a race condition in the Copilot Chat feature of Microsoft Edge that permits an authorized attacker to read data transmitted over the network. Concurrent execution of a shared resource without proper synchronization enables the attacker to capture confidential information during transient timing windows. The effect is the disclosure of sensitive data, which may include credentials, user queries, or other content managed through Copilot Chat.
Affected Systems
The affected product is Microsoft Edge (Chromium‑based) as supplied by Microsoft. All builds that contain the Copilot Chat component are potentially impacted, but no specific version range is listed in the available data.
Risk and Exploitability
The CVSS score of 4.4 suggests moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack is likely local or requires authorized access to the browser, with exploitation relying on a brief timing window inherent to the race condition. No remote exploitation path is documented, so the risk is modest but warrants attention and monitoring for patches.
OpenCVE Enrichment