CVE-2026-33111

7.5

Microsoft · Edge

A command injection vulnerability in Microsoft Copilot Chat via Microsoft Edge allows unauthorized attackers to disclose sensitive network information.

Executive summary

A command injection vulnerability in Microsoft Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

Vulnerability

This flaw involves improper neutralization of special elements used in a command, known as command injection, allowing unauthenticated attackers to execute arbitrary commands over the network.

Business impact

Successful exploitation of this vulnerability can lead to unauthorized information disclosure, exposing sensitive network and system data. Given the CVSS score of 7.5, the risk is classified as high because it enables remote attackers to access restricted information without requiring authentication or user interaction.

Remediation

Immediate Action: Apply the vendor security updates immediately as outlined in the official Microsoft advisory.

Proactive Monitoring: Monitor network traffic for anomalous command patterns or unexpected outbound data transfers originating from the browser environment.

Compensating Controls: Deploy network intrusion detection systems and web filtering solutions to monitor and block abnormal requests targeting the affected component.

Exploitation status

Public Exploit Available: No (false)

Analyst recommendation

Organizations running Microsoft Edge with Copilot Chat must treat this high-severity vulnerability with urgency. Administrators should apply the official vendor patches promptly to eliminate the risk of unauthorized information disclosure.

More Microsoft CVEs

Sources