potential privacy/security incident involving Copilot.

James R Brawner Jr 0 Reputation points
2026-05-06T20:51:19.9733333+00:00

Hello Microsoft Support,

I’m reporting a potential privacy/security incident involving Copilot. The assistant returned a block of my Edge browser tabs metadata in the chat output. This metadata includes tab titles and URLs from my current browsing session and should not have been exposed.

Incident details and had same issue a few days ago and i reported and it cleared up but came back again today

When: Wednesday, 06 May 2026, 11:46 AM EDT (local time)

Where: Copilot chat session in Microsoft Edge on my device

Device: [insert OS and version, e.g., Windows 11 22H2]

Browser: Microsoft Edge [insert exact version from edge → Settings → About]

Description: The Copilot response included a JSON block labeled edge_all_open_tabs containing pageTitle, pageUrl, tabId, and isCurrent. I did not expect browsing metadata to be included in assistant output or in files intended for third parties.

Requested actions

Confirm whether this is a bug and whether any of the metadata was logged, stored, or transmitted outside my session.

Remove any stored copies of the edge_all_open_tabs block tied to my account or session.

Explain why the metadata appeared in the assistant output and what safeguards will be applied to prevent recurrence.

I am about to go out so i won't be available to correspond until tomorrow or later.

Thank you once again for your excellent customer service especially by Mr S. Shreyas, he was most helpful and professional

Sincerely

James R Brawner Jr

Microsoft Copilot | Microsoft 365 Copilot | Development
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-06T20:51:51.9733333+00:00

    Copilot in Microsoft Edge can use browsing context (including page titles and URLs) to improve responses when allowed by the browser settings and by the user during a session.

    Key behaviors from the documented design:

    1. How Edge shares browsing context with Copilot
    • When using Copilot Chat in Edge, browsing context (such as the current page URL and title) may be sent to Copilot to provide more relevant responses.
    • If the user grants permission to share page information, Microsoft Edge sends:
      • Browsing context of the given session
      • The user’s prompt
      • Previous conversation history
    • This information is used only to generate a meaningful response in that session.
    • Enterprise data protection applies to Copilot Chat prompts and responses when signed in with a Microsoft Entra account.
    1. Control over whether Copilot can use browser content
    • In Microsoft Edge, the ability for Copilot to use browser content is controlled by a setting:
      • Go to SettingsOther appearance settingsCopilot and sidebarCopilot.
      • Use the Allow Copilot to use browser content toggle to control whether page content is available to Copilot.
    • If this toggle is off, Copilot should not use browser content as context.
    1. What is stored vs. not stored
    • Conversation history (queries and responses) is stored until explicitly deleted. This is independent of whether Copilot is used in Edge, Bing, or on the Copilot site.
    • Page content itself (for example, the full content of a web page or video transcript) is not stored as part of Copilot history.
    • With enterprise data protection, prompts and responses in Copilot Chat are logged, and the same retention policies used for Microsoft 365 Copilot can be applied to Copilot Chat. These logs enable features like returning to previous chats.
    • Web search queries generated for grounding responses are:
      • Derived from the prompt into a few words.
      • Sent via secure connection to the Bing search service.
      • Stripped of user and tenant identifiers.
      • Not shared with advertisers and not used to train foundation LLMs.
    1. Visibility into web queries
    • Copilot shows web search query citations in the linked citation section of responses.
    • These citations show the exact generated search queries and the sites used, and are available in the chat thread for 24 hours.
    1. Deleting conversation history
    • Conversation history with Copilot can be deleted:
      • Go to the Privacy Dashboard.
      • Select Browsing and searchCopilot activity historyClear all.
    • This removes stored Copilot conversation history associated with the account.
    1. Logging and retention controls
    • With enterprise data protection, prompts and responses are subject to Microsoft 365 retention policies and audit logging.
    • Administrators can configure retention policies and audit settings as described in the referenced documentation.
    1. Web queries vs. internal data
    • Web queries sent to Bing are handled under the Microsoft Services Agreement and Microsoft Privacy Statement and are processed by Bing as an independent data controller.
    • Generated web search queries do not include:
      • User or tenant identifiers
      • The full prompt (unless very short)
      • Entire uploaded files
      • Entire web pages or PDFs summarized by Copilot in Edge

    Given this design, the appearance of browsing metadata (such as tab titles and URLs) in a Copilot response is consistent with scenarios where Edge is allowed to share browser content with Copilot and that content is used as context. However, the documentation does not describe a behavior where an internal structure like edge_all_open_tabs is intentionally surfaced verbatim in the user-visible output. That specific behavior would require investigation by Microsoft Support/Engineering as a potential defect in how context is being surfaced.

    To address the concerns using documented controls:

    1. Limit or disable browser content sharing with Copilot
    • In Edge, turn off Allow Copilot to use browser content under Other appearance settingsCopilot and sidebarCopilot.
    • This reduces or prevents browsing metadata from being used as context.
    1. Clear Copilot conversation history
    • Use the Privacy Dashboard’s Copilot activity historyClear all to remove stored conversations, including any responses that may contain the edge_all_open_tabs block.
    1. Rely on enterprise data protection and retention policies
    • For Microsoft 365 Copilot with enterprise data protection, prompts and responses are logged under Microsoft 365 controls.
    • Administrators can apply retention policies and audit logging to manage how long this data is kept and how it is accessed.
    1. Understand web query handling
    • Any web queries generated from the prompt (including terms derived from active content in Edge) are sent to Bing without user or tenant identifiers and are not used to train foundation LLMs.

    For a full incident investigation (including confirmation of whether a specific edge_all_open_tabs payload was logged or transmitted and targeted deletion of that specific data), direct engagement with Microsoft Support is required, as those actions depend on back-end access and support workflows that are not exposed through public documentation.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    3 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.