External risk intelligence

Microsoft 365 Copilot Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-41090

The vulnerability affects Microsoft 365 Copilot on the iPhone OS platform. This is a client-side end-user application running on a mobile device, which is not an internet-facing service, edge gateway, or public-facing server that would be exposed to inbound connections from the public internet in standard deployment patterns.

Command Injection

Microsoft 365 Copilot

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in Microsoft Copilot, a command injection vulnerability that could allow an unauthorized attacker to tamper with the system over a network. The main concern at this time is to confirm if our environment utilizes the affected technology.

  • Attackers could alter system commands remotely.
  • Understand if Copilot on iPhone is in use.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into interacting with a specially crafted input. This could allow them to tamper with the application's functionality and potentially access or modify sensitive information.

  • Requires user interaction.
  • Triggered by specially crafted input.
  • Risk of unauthorized tampering.

Live Threat

Current exploitation, exposure, and threat context

An unauthorized attacker could tamper with Microsoft 365 Copilot over a network. This could impact the service's behavior when an affected user interacts with it.

  • Service behavior could be tampered with.
  • Via a network connection.
  • Unpredictable service outcomes.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Microsoft 365 Copilot on iOS requires user interaction and is not directly exposed to the internet, meaning it is unlikely to be a first target for external attackers. However, internal actors or those who gain initial access could exploit it. The first step is to confirm the presence of the affected application, assess its business criticality, and identify the accountable owner for remediation or mitigation.

  • Identify Copilot app owners.
  • Verify user interaction, business criticality.
  • Plan user-focused mitigation or remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft 365 Copilot?

Microsoft 365 Copilot is an AI-powered productivity assistant integrated into the Microsoft 365 ecosystem. It helps users summarize documents, draft emails, and analyze data across applications. This specific vulnerability affects the mobile application version designed for iPhone OS, which users install on their devices to access these AI-driven features while on the go.

What does command injection mean for CVE-2026-41090?

This vulnerability, classified as CWE-77, occurs when an application fails to properly sanitize special characters in user-provided input. In the context of CVE-2026-41090, this flaw allows an attacker to inject their own malicious commands into the system. If successful, the software might execute these unintended instructions, potentially allowing the attacker to tamper with the application's functionality or the information it handles.

How is this vulnerability triggered?

An attacker triggers this flaw by tricking a user into interacting with specially crafted input, such as a malicious link or file. It is important to note that the vulnerability is not triggered automatically by simply being connected to a network. It specifically requires the user to perform an action within the app, such as clicking or opening a deceptive element, to initiate the unintended command execution.

Is my environment at risk from this CVE?

According to Halo Surface Signal, this vulnerability is considered unlikely to be a primary target for external attackers. Because the issue resides in a client-side mobile application rather than a public-facing server or internet-exposed gateway, it lacks a direct path for remote exploitation from the public internet. The risk is generally limited to scenarios where an attacker can influence the mobile user's interaction directly.

What should I do if we use this software?

Your first step is to perform an inventory to identify which devices have the Microsoft 365 Copilot mobile app installed. Determine who the accountable business owners are for these devices and assess how critical the app is to their daily workflows. Focus on verifying if users are aware of the risks of interacting with untrusted inputs while using mobile applications, as user awareness is a key defense for this specific type of flaw.

References