Microsoft Copilot Personal 'CoSnitch' Flaws Let One Click Steal Your Data: Patches Issued August 18, 2026
Security researchers at Varonis Threat Labs discovered a set of vulnerabilities, collectively named CoSnitch (CVE-2026-24301), in Microsoft Copilot Personal that allowed a single click to exfiltrate sensitive data from connected applications. Microsoft issued patches for these flaws on August 18, 2026, after Varonis reported the issues in December 2025. For broader context, explore our AI News.
Understanding the CoSnitch Vulnerabilities
The CoSnitch vulnerabilities encompass three distinct flaws within Microsoft Copilot Personal. The primary attack vector leveraged an undocumented URL parameter, autorun=1, in conjunction with the q parameter. This combination allowed an attacker to automatically execute a malicious prompt within a victim's authenticated Copilot session.
This method exploited the existing access permissions users had granted to Copilot, rather than requiring new authorizations. The attack could lead to the exfiltration of sensitive data from connected applications, including email accounts, calendars, Google Drive, prior chat histories, and saved user instructions.
Data at Risk from CoSnitch
The types of data susceptible to exfiltration through the CoSnitch attack included:
- Mail Accounts: Message bodies, subject lines, and sender/recipient metadata.
- Calendars: Detailed event information.
- Google Drive: File names and summaries.
- Copilot Chat History: Full records of past conversations.
- Saved Instructions: User-defined persistent instructions for Copilot.
The Memory-Poisoning Vulnerability
Beyond the one-click data exfiltration, Varonis Threat Labs also uncovered a memory-poisoning vulnerability. This flaw allowed a specially crafted web page, when summarized by Copilot, to inject attacker-supplied instructions directly into the user's persistent memory store. These injected instructions demonstrated remarkable persistence, surviving even after actions such as password changes, session revocations, and device re-enrollment.
This aspect of the vulnerability highlights a potential for long-term compromise, where malicious instructions could influence Copilot's behavior over extended periods without immediate detection.
Timeline of Discovery and Patching
Varonis Threat Labs reported the CoSnitch vulnerabilities to Microsoft in December 2025. Microsoft subsequently developed and deployed patches to address these issues, which were released on August 18, 2026. Prior to the patch release, Varonis found no evidence that the CoSnitch vulnerabilities had been exploited in the wild.
Implications for AI Assistant Security
The discovery of CoSnitch underscores a broader security challenge for frontier AI assistants. The researchers noted that these advanced models can be socially engineered at the model layer to reveal internal defenses, a technique they termed 'meta-hacking.' This suggests that traditional security paradigms may need to evolve to account for the unique vulnerabilities inherent in AI systems that interact with user data and external services.
Users of Microsoft Copilot Personal are advised to ensure their applications are updated to the latest versions to benefit from the security patches issued on August 18, 2026.
Sources
- Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data · Issue #438 · wiz-sec/open-cvdb · GitHub
- EchoLeak: The First Real-World Zero-Click Prompt...
- Copilot modifying workspace settings.json with personal preferences · Issue #8555 · microsoft/vscode-copilot-release · GitHub
- GitHub - 8kSec/awesome-ai-security: A practitioner-focused reference for AI/ML security — attacks, tools, research, and defenses. Covers offensive AI, securing AI systems, AI-assisted security operations, and governance. · GitHub
- [FEATURE] Tool result transform hook for content sanitization · Issue #18653 · anthropics/claude-code · GitHub
Recommended AI tools
Lakera
Code Assistance
The leading security platform to secure your AI future
Beagle Security
Code Assistance
The AI-powered AppSec platform for enterprise-grade security
KushoAI
Code Assistance
Empowering Language Intelligence
huntr
Code Assistance
Streamline your job search
Adversa AI
Scientific Research
Securing AI Against Adversarial Threats
Maced
Code Assistance
Maced AI | Autonomous AI Pentesting Platform
Was this article helpful?
Found outdated info or have suggestions? Send us a note.