CVE-2026-58616Moderate
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Assessment
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
- Severity
- Moderate
- CVSS base score
- 4.4CVSS:3.1/
AV:N/ AC:H/ PR:L/ UI:R/ S:C/ C:L/ I:L/ A:N/ E:U/ RL:O/ RC:C - Impact
- Information Disclosure
- EPSS, next 30 days
- 0.3%Higher than 19.8% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Unlikely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Copilot Chat (Microsoft Edge)
- Weakness
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- Issued by
- Microsoft
- Published
- 28 Aug 2026 · August 2026
- Last revised
- 28 Aug 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Browser6 affected products
- Microsoft Edge (Chromium-based)
- Microsoft Edge for Android
- Microsoft Edge for iOS
- Microsoft Edge for Linux
- Microsoft Edge for MAC
- Microsoft Edge for Windows