Impact
The vulnerability is an improper access control flaw, categorized as CWE‑284, that allows an unauthorized attacker to elevate privileges in Microsoft 365 Copilot for iOS when communicating over a network. An attacker who can reach the Copilot service can gain higher‑level permissions than normally permitted, potentially enabling unauthorized actions within the application.
Affected Systems
The affected product is Microsoft 365 Copilot for iOS. The vulnerability applies to all deployed instances of the app until a patch is applied; no specific version range is indicated.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% indicates a low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based adversary who can send or intercept requests to the Copilot service to manipulate privilege levels.
OpenCVE Enrichment