CVE-2026-58616: Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
Other sources
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53
Event History
Frequently Asked Questions
What level of access and interaction does an attacker need?
The attacker must already be authorized with low privileges and must be able to exploit the issue over a network. Exploitation also requires user interaction and has high attack complexity.
What is the expected impact if exploitation succeeds?
The vulnerability may allow disclosure of information. The supplied metrics also indicate limited confidentiality and integrity impact, with no availability impact.
Which products are identified as affected?
The affected software listed is Microsoft Edge and Microsoft Edge (Chromium-based), specifically involving Copilot Chat in Microsoft Edge.