Microsoft Edge Copilot Remote Code Execution Vulnerability
Published July 14, 2026Updated July 24, 2026
Source data
Overview
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
Impact & technical details
Remote Code Execution
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to execute code on the Hyper-V host execution environment.
How could an attacker exploit this vulnerability? An attacker could host a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot on a user’s device when the user visits the site. Because the affected component processes these requests without confirmation or origin checks, the prompts may be executed without the user’s awareness, potentially resulting in unintended actions within Copilot such as accessing or modifying data.
- CVSS base score
- Not supplied
Affected products
- Microsoft Edge Copilot for Android
- Microsoft Edge Copilot for IOS
Source guidance
Remediation
- Release Notes
Patch availability is not confirmed by this dataset. Consult the vendor before selecting a remediation.
GTP recommendation · Rule-based guidance
Recommended next step
Review affected Microsoft products and apply the applicable security updates through your organization's normal patch-management process. Confirm availability and prerequisites in the Microsoft advisory.
Authoritative sources & updates
Findings and update information come from the linked publishers. GTP compiles the public record and provides the recommendation above. CVSS ratings shown here come from Microsoft. NVD references provide additional public context.
Managed by GTP?
Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.
Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.
