Skip to main content
Griffin Technology PartnersGTP
CriticalCVE-2026-48561active

Microsoft Edge Copilot Remote Code Execution Vulnerability

Published July 14, 2026Updated July 24, 2026

Source data

Overview

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

Impact & technical details

Remote Code Execution

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to execute code on the Hyper-V host execution environment.

How could an attacker exploit this vulnerability? An attacker could host a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot on a user’s device when the user visits the site. Because the affected component processes these requests without confirmation or origin checks, the prompts may be executed without the user’s awareness, potentially resulting in unintended actions within Copilot such as accessing or modifying data.

CVSS base score
Not supplied

Affected products

  • Microsoft Edge Copilot for Android
  • Microsoft Edge Copilot for IOS

Source guidance

Remediation

  • Release Notes

Patch availability is not confirmed by this dataset. Consult the vendor before selecting a remediation.

GTP recommendation · Rule-based guidance

Recommended next step

Review affected Microsoft products and apply the applicable security updates through your organization's normal patch-management process. Confirm availability and prerequisites in the Microsoft advisory.

Authoritative sources & updates

Findings and update information come from the linked publishers. GTP compiles the public record and provides the recommendation above. CVSS ratings shown here come from Microsoft. NVD references provide additional public context.

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.