Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Date Jun 9, 2026
Type Patch Tuesday
Signal High-risk advisory
Vendor / Product Microsoft ยท Copilot Chat (Microsoft Edge)
CVE CVE-2026-47644
High-risk advisory CVE-2026-47644

Summary

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates. EPSS percentile: 50%.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-47644. Confirm whether Copilot Chat (Microsoft Edge) is deployed, then apply the current security update or documented mitigation. CVSS score: 6.5. EPSS probability: 0.7%; percentile: 50%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.