CVE-2026-26133: Microsoft 365 Copilot Information Disclosure Flaw


Lookout Coverage and Recommendation for Admins
Android applications have already been covered by more recent CVEs, including CVE-2026-45649. iOS support was released on September 8, 2026. This rollout was prioritized due to the vulnerability's high CVSS score, the rapid enterprise adoption of Microsoft 365 Copilot across mobile endpoints, and its direct fit within Lookout's mobile and content threat protection framework. Once active, the platform will automatically trigger alerts and response workflows according to each organization's configured risk thresholds and escalation policies.
To ensure mobile endpoints are protected, Lookout administrators should take the following actions in the Lookout console:
- Maintain App & Service Updates — Ensure all 19 impacted Microsoft client apps across iOS and Android (including Teams, Office, Copilot, PowerBI, Edge, and Outlook) are fully updated to the latest builds containing Microsoft's patch mitigations.
- Remediate Application Versions — Enforce conditional access policies via enterprise EMM/MDM portals to block non-compliant mobile devices running unpatched versions of affected iOS and Android productivity apps.
- Enable Lookout Phishing & Content Protection (PCP) — As defense in depth, activate PCP across all enrolled endpoints to inspect and block malicious URLs, documents, and web links serving prompt injection payloads.
- Monitor Telemetry & Audit Logs — Review Microsoft 365 audit logs for abnormal prompt extraction patterns, unusual API calls, or anomalous data access behavior targeting LLM integrations.
Overview
Microsoft disclosed a high-severity security vulnerability in March 2026 affecting Microsoft 365 Copilot and embedded Copilot components across mobile enterprise applications: CVE-2026-26133.
CVE-2026-26133 is an AI Command Injection flaw caused by improper neutralization of special elements in prompt/context inputs passed to the underlying model engine (CWE-77 / CWE-200). Tracked with a CVSS 3.1 base score of 7.1 (High), this vulnerability enables an attacker to execute a network-based attack via indirect prompt injection to expose sensitive tenant information or internal runtime context.
The flaw impacts 19 total mobile applications across iOS and Android ecosystems:
- iOS Apps (10): Microsoft 365 Copilot, Microsoft Teams, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Outlook, Microsoft OneNote, Microsoft Loop, Microsoft PowerBI, and Microsoft Edge.
- Android Apps (9): Microsoft 365 Copilot, Microsoft Teams, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Outlook, Microsoft OneNote, Microsoft PowerBI, and Microsoft Edge.
More details are available from Microsoft: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133
CVE-2026-26133 has been patched in Microsoft 365 Copilot for iOS starting with version 2.107.2 and Microsoft 365 Copilot for Android starting with version 16.0.19815.10000. Devices running versions below these thresholds may be vulnerable and should be updated immediately.
There is no reported active exploitation in the wild at this time, and official security mitigations have been released by Microsoft. Organizations are advised to enforce immediate remediation across all mobile enterprise deployments to mitigate potential corporate data exposure.
Lookout Analysis
This vulnerability presents a high risk to corporate environments because an attacker can embed malicious prompt instructions within shared documents, emails, or web pages processed by Microsoft 365 Copilot components. When an enterprise user requests Copilot to summarize or analyze the crafted content, the AI engine processes the untrusted input, allowing instructions to break context boundaries and leak unauthorized data.
Based on the CVE description and CWE-77 characteristics, a plausible exploitation chain would proceed as follows:
- Delivery — The attacker places a specially crafted payload (indirect prompt injection) inside a shared document, message, or external link accessible to the target user.
- Triggering — The user asks Microsoft 365 Copilot or an integrated mobile Office app to summarize, process, or query the content containing the hidden payload.
- AI Command Injection — Unsanitized prompt instructions pass through internal context boundaries, executing as system-level directives within the AI reasoning engine.
- Data Leakage — Copilot returns unauthorized tenant data, internal document summaries, or sensitive context back to the attacker-accessible response or external channel.
- Post-Exploitation — The attacker leverages the leaked corporate information to conduct secondary phishing, credential theft, or broader enterprise compromise.
Authors


Lookout Mobile Endpoint Security
Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.
Advanced mobile Endpoint Detection & Response powered by data from 185M+ apps and 200M+ devices on iOS, Android, ChromeOS.

