{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Public",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "general",
        "text": "To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle",
        "title": "Additional Resources"
      },
      {
        "category": "legal_disclaimer",
        "text": "The information provided in the Microsoft Knowledge Base is provided \\\"as is\\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.",
        "title": "Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "secure@microsoft.com",
      "name": "Microsoft Security Response Center",
      "namespace": "https://msrc.microsoft.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability - VEX",
        "url": "https://msrc.microsoft.com/csaf/vex/2026/msrc_cve-2026-58616.json"
      },
      {
        "category": "external",
        "summary": "Microsoft Support Lifecycle",
        "url": "https://support.microsoft.com/lifecycle"
      },
      {
        "category": "external",
        "summary": "Common Vulnerability Scoring System",
        "url": "https://www.first.org/cvss"
      }
    ],
    "title": "Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability",
    "tracking": {
      "current_release_date": "2026-08-28T07:00:00.000Z",
      "generator": {
        "date": "2026-09-25T19:35:13.963Z",
        "engine": {
          "name": "MSRC Generator",
          "version": "1.0"
        }
      },
      "id": "msrc_CVE-2026-58616",
      "initial_release_date": "2026-08-28T07:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-08-28T07:00:00.000Z",
          "legacy_version": "1",
          "number": "1",
          "summary": "Information published."
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for Android <152.0.4191.52",
                  "product_id": "5"
                }
              },
              {
                "category": "product_version",
                "name": "152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for Android 152.0.4191.52",
                  "product_id": "11815"
                }
              }
            ],
            "category": "product_name",
            "name": "Microsoft Edge for Android"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for MAC <152.0.4191.52",
                  "product_id": "3"
                }
              },
              {
                "category": "product_version",
                "name": "152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for MAC 152.0.4191.52",
                  "product_id": "12480"
                }
              }
            ],
            "category": "product_name",
            "name": "Microsoft Edge for MAC"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for iOS <152.0.4191.52",
                  "product_id": "4"
                }
              },
              {
                "category": "product_version",
                "name": "152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for iOS 152.0.4191.52",
                  "product_id": "11966"
                }
              }
            ],
            "category": "product_name",
            "name": "Microsoft Edge for iOS"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for Linux <152.0.4191.52",
                  "product_id": "2"
                }
              },
              {
                "category": "product_version",
                "name": "152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for Linux 152.0.4191.52",
                  "product_id": "21776"
                }
              }
            ],
            "category": "product_name",
            "name": "Microsoft Edge for Linux"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "<152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for Windows <152.0.4191.52",
                  "product_id": "1"
                }
              },
              {
                "category": "product_version",
                "name": "152.0.4191.52",
                "product": {
                  "name": "Microsoft Edge for Windows 152.0.4191.52",
                  "product_id": "21777"
                }
              }
            ],
            "category": "product_name",
            "name": "Microsoft Edge for Windows"
          }
        ],
        "category": "vendor",
        "name": "Microsoft"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-58616",
      "cwe": {
        "id": "CWE-362",
        "name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"
      },
      "notes": [
        {
          "category": "general",
          "text": "Microsoft",
          "title": "Assigning CNA"
        }
      ],
      "product_status": {
        "fixed": [
          "11655",
          "11815",
          "12480",
          "11966",
          "21776",
          "21777"
        ],
        "known_affected": [
          "5",
          "3",
          "4",
          "2",
          "1"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability - VEX",
          "url": "https://msrc.microsoft.com/csaf/vex/2026/msrc_cve-2026-58616.json"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-28T07:00:00.000Z",
          "details": "152.0.4191.52:Security Update:https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security",
          "product_ids": [
            "5",
            "3",
            "4",
            "2",
            "1"
          ],
          "url": "https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "exploitCodeMaturity": "UNPROVEN",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "scope": "CHANGED",
            "temporalScore": 3.9,
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C",
            "version": "3.1"
          },
          "products": [
            "1",
            "2",
            "3",
            "4",
            "5",
            "6"
          ]
        }
      ],
      "title": "Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability"
    }
  ]
}