Frozen view of version 16.0.17928.20046 — CVE statuses are recomputed against this version.
View current version
Android
Microsoft Corporation
Microsoft 365 Copilot
- Known vulnerabilities
- 27
- Still open
- 16
- KEV open
- 0
- Max CVSS score
- 9.8
50
Security Score
Concerning · 50/100
Composite: 50% open CVEs + 40% open KEVs + 10% vendor velocity.
See breakdown
- Open CVEs -50/-50 16 CVEs
- Open KEVs 0/-40 0 KEVs
- Vendor 0/-10 100% fresh
92
Privacy Score
Respectful · 92/100
Composite: 40% critical shared + 30% high shared + 20% high collected + 10% sensitive density.
See breakdown
- Critical shared 0/-40 0 critical shared
- High shared 0/-30 0 high + 0 medium shared
- High collected -8/-20 1 high + 11 medium collected
- Sensitive density 0/-10 7% sensitive
Test a different version
Evaluates the risk for a given version (default: current store version).
Description
Create content, explore ideas, and get answers with Copilot.
Data collected and shared
Source: Play Store Data Safety · 15 data item(s) declared
1 High
11 Medium
3 Low
Purchase history
App interactions
In-app search history
Installed apps
Other actions
Other user-generated content
Files and docs
Approximate location
Email address
Other info
Phone number
Photos and Videos
Crash logs and Diagnostics
Device or other IDs
User IDs
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
Known vulnerabilities (CVE)
16 open
10 undetermined
1 fixed
| CVE | Status | Severity | KEV | Published | Fixed in |
|---|---|---|---|---|---|
|
CVE-2026-26134
HIGH 7.8
Fixed in: 16.0.19822.20000
|
Open | HIGH 7.8 | — | 16.0.19822.20000 | |
|
CVE-2026-26110
HIGH 8.4
Fixed in: 16.0.19822.20000
|
Open | HIGH 8.4 | — | 16.0.19822.20000 | |
|
CVE-2026-25180
MEDIUM 5.5
Fixed in: 16.0.19822.20000
|
Open | MEDIUM 5.5 | — | 16.0.19822.20000 | |
|
CVE-2026-24285
HIGH 7.0
Fixed in: 16.0.19822.20000
|
Open | HIGH 7.0 | — | 16.0.19822.20000 | |
|
CVE-2025-62557
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-62554
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-62199
HIGH 7.8
Fixed in: 16.0.19426.20044
|
Open | HIGH 7.8 | — | 16.0.19426.20044 | |
|
CVE-2025-60724
CRITICAL 9.8
Fixed in: 16.0.19426.20044
|
Open | CRITICAL 9.8 | — | 16.0.19426.20044 | |
|
CVE-2025-59234
HIGH 7.8
Fixed in: 16.0.19328.20000
|
Open | HIGH 7.8 | — | 16.0.19328.20000 | |
|
CVE-2025-59227
HIGH 7.8
Fixed in: 16.0.19328.20000
|
Open | HIGH 7.8 | — | 16.0.19328.20000 | |
|
CVE-2025-53799
MEDIUM 5.5
Fixed in: 16.0.19220.20000
|
Open | MEDIUM 5.5 | — | 16.0.19220.20000 | |
|
CVE-2025-53766
CRITICAL 9.8
Fixed in: 16.0.19127.20000
|
Open | CRITICAL 9.8 | — | 16.0.19127.20000 | |
|
CVE-2025-53732
HIGH 7.8
Fixed in: 16.0.19127.20000
|
Open | HIGH 7.8 | — | 16.0.19127.20000 | |
|
CVE-2025-49702
HIGH 7.8
|
Unknown | HIGH 7.8 | — | — | |
|
CVE-2025-49697
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-49695
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-49696
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-47953
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-47167
HIGH 8.4
Fixed in: 16.0.18925.20000
|
Open | HIGH 8.4 | — | 16.0.18925.20000 | |
|
CVE-2025-47164
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-47162
HIGH 8.4
|
Unknown | HIGH 8.4 | — | — | |
|
CVE-2025-30386
HIGH 8.4
Fixed in: 16.0.18827.20000
|
Open | HIGH 8.4 | — | 16.0.18827.20000 | |
|
CVE-2025-30388
HIGH 7.8
Fixed in: 16.0.18827.20000
|
Open | HIGH 7.8 | — | 16.0.18827.20000 | |
|
CVE-2025-26687
HIGH 7.5
Fixed in: 16.0.18730.20000
|
Open | HIGH 7.5 | — | 16.0.18730.20000 | |
|
CVE-2025-21338
HIGH 7.8
Fixed in: 16.0.18429.20000
|
Open | HIGH 7.8 | — | 16.0.18429.20000 | |
|
CVE-2023-36565
HIGH 7.0
Fixed in: 16.0.16827.20138
|
Fixed | HIGH 7.0 | — | 16.0.16827.20138 | |
|
CVE-2023-23391
MEDIUM 5.5
|
Unknown | MEDIUM 5.5 | — | — |
Other apps by this publisher
Apps published by Microsoft Corporation
Microsoft Loop
com.microsoft.loop
1 open
Microsoft OneDrive
com.microsoft.skydrive
1 open
Windows Camera
msstore:9WZDNCRFJBBG
No known vulnerability
Dynamics 365 for Phones
com.microsoft.crm.crmphone
No known vulnerability
Dynamics 365 Sales
com.microsoft.crm.crmphone.sales
No known vulnerability
HEIF Image Extension
msstore:9PMMSR1CGPWG
No known vulnerability