CVE-2026-48561

Summary

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Edge Copilot for Android1.0.0 < publicationaffected
MicrosoftMicrosoft Edge Copilot for IOS1.0.0 < publicationaffected

Weaknesses

  • CWE-77: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References