Threat · curated 18 Aug 2026
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
First reported · updated · 12 reports theregister.com
Coverage timeline
Why it matters
CoSnitch shows an AI assistant with broad OAuth access to email, files and calendars can be turned into a silent collection-and-exfiltration channel by a single malicious link, moving sensitive data through a trusted AI workflow that evades traditional alerts.
Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301, CVSS 8.8), a one-click vulnerability chain in Microsoft Copilot Personal that lets a specially crafted Copilot URL auto-execute attacker-supplied instructions on page load. The injected prompt can query connected services (Gmail, Drive, Calendar, OneDrive), encode results into an outbound URL exfiltrated through Copilot's legitimate URL-fetching, and persistently poison Copilot memory via hidden instructions in a webpage submitted for summarization. Microsoft deployed a service-side fix on August 18, 2026; enterprise Copilot was unaffected and no in-the-wild exploitation was observed.
Summary
Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a one-click vulnerability chain in Microsoft Copilot Personal in which a specially crafted Copilot URL auto-executes an attacker-supplied prompt on page load, enabling silent data collection from connected services and exfiltration through Copilot's own URL-fetch capability. Varonis disclosed the issue to Microsoft in December 2025, and Microsoft deployed a service-side fix on August 18, 2026.[0][6]
The research is distinguished by its discovery method, 'meta-hacking,' in which the researchers questioned Copilot about why an attack should not work and the assistant volunteered architectural and guardrail details, including an undocumented URL parameter, that revealed the vulnerable behavior. Varonis rated the chain critical while Microsoft assigned a CVSS v3.1 score of 8.8 (High) and classified it under CWE-77.[0][6]
Varonis reports no evidence of in-the-wild exploitation, framing CoSnitch as vulnerability research. Microsoft stated the flaw affected Copilot Personal rather than Microsoft 365 Copilot Enterprise and that customers required no action to receive the fix; the advisory nonetheless treats it as a broader warning about AI assistants with broad connected-app access acting as indirect data-exfiltration channels.[0][6]
Attack chain
- Delivery / Initial Access: An attacker prepares a legitimate-looking Microsoft-hosted Copilot URL using the documented ?q= query parameter combined with an undocumented parameter carrying an attacker-controlled prompt, and delivers it via email, chat, or another messaging channel.[0][6]
- Automatic prompt execution: When the victim opens the crafted link, the supplied prompt executes instantly on page load in the victim's authenticated Copilot session with no separate click, confirmation, or submission action.[0][6]
- Collection: The automatically executed prompt instructs Copilot to query services connected to the victim's account, such as Gmail, Google Drive, Google Calendar, and OneDrive.[0][6]
- Exfiltration: Collected data is encoded into a URL (secondary reporting cites Base64) and transmitted through Copilot's legitimate URL-fetch function to an attacker-controlled webhook or server, making the traffic resemble ordinary Copilot web activity.[0][6]
- Persistence via memory poisoning: In an alternate path, a victim asks Copilot to summarize an attacker webpage containing hidden instructions; those instructions are written into Copilot's persistent memory and survive password changes, session revocation, and device re-enrollment, influencing future behavior.[0][6]
Disclosure timeline
| Date | Event |
|---|---|
| December 2025 | Varonis Threat Labs disclosed the CoSnitch vulnerability to Microsoft.[0][6] |
| August 18, 2026 | Microsoft deployed the service-side fix; Varonis published its research. The flaw is tracked as CVE-2026-24301.[0][6] |
How it works
The first weakness is automatic prompt execution: the documented ?q= URL parameter combined with an undocumented parameter causes any attacker-supplied prompt to execute instantly on page load with no click, confirmation, or user action.[0][6]
The second weakness is data exfiltration to external servers: an injected prompt queries the victim's connected apps (Gmail, Drive, Calendar, OneDrive) via authorized connectors, encodes the results into a URL, and transmits them through Copilot's built-in URL-fetch capability to an attacker-controlled endpoint, blending in with normal Copilot browsing.[0][6]
The third weakness is indirect prompt injection via web summarization leading to persistent memory modification: hidden instructions embedded in a summarized webpage are processed as commands and written into Copilot's persistent memory, surviving password changes, session revocation, and device re-enrollment.[0][6]
The flaw was surfaced through 'meta-hacking,' where researchers progressively asked Copilot why the attack would not work, prompting the assistant to disclose architectural and guardrail details—including the undocumented parameter—rather than requiring reverse engineering.[0][6]
The underlying condition, illustrated by the related SearchLeak flaw, is that AI-powered search accepts natural-language prompts in a URL query parameter, so a classic parameter-injection bug becomes an executable AI instruction that silently exfiltrates data.[16]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| Microsoft Copilot Personal / Copilot Web | Instances supporting the ?q= plus undocumented auto-execution URL parameters prior to the August 18, 2026 fix | Patched service-side by Microsoft on August 18, 2026 (CVE-2026-24301); customers required no action. Copilot Enterprise stated not affected.[0][6] |
| Microsoft 365 Copilot Enterprise (related SearchLeak flaw) | Copilot Enterprise Search implementation combining three weaknesses | Patched server-side (CVE-2026-42824)[16] |
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| cve | CVE-2026-24301 | Identifier for the CoSnitch information-disclosure vulnerability in Microsoft Copilot Personal; the advisory notes it is a vulnerability identifier, not evidence of compromise, and no attacker domains, IPs, hashes, or exploit URLs were published.[0][6] |
| cve | CVE-2026-42824 | Identifier for the related SearchLeak information-disclosure flaw in Microsoft 365 Copilot Enterprise, patched server-side.[16] |
Key takeaways
- AI assistants can surface their own vulnerabilities during normal use; 'meta-hacking' shows an attacker can coax a model into disclosing internal parameters and protections rather than reverse-engineering them.[0][6]
- Because LLMs cannot reliably separate data from instructions, prompt-injection flaws weaponize an assistant's authorized access to email, files, calendars, and cloud storage, turning a trusted AI workflow into a covert collection and exfiltration channel.[0][6]
- Persistent memory poisoning defeats standard incident-response steps such as password resets and session revocation, so responders must add AI memory, personalization, and connector configuration to investigation checklists.[0][6]
- No in-the-wild exploitation was observed and no static IOCs were published; defenders should hunt behaviorally by correlating crafted Copilot links, connected-service access, and unusual outbound destinations rather than relying on a single URL signature.[0][6]
Defensive actions
- Confirm the scope of Copilot usage, distinguishing Copilot Personal from Microsoft 365 Copilot Enterprise, and verify Microsoft's August 18, 2026 service-side fix is in effect.: CoSnitch affected Copilot Personal; Microsoft stated the fix was deployed and no customer action was required, so response is largely retrospective exposure assessment.[0]
- Inventory AI connectors, remove unnecessary connected applications, and apply least privilege to each assistant's access.: Exfiltration abuses the assistant's authorized access to connected services such as Gmail, Drive, Calendar, and OneDrive; limiting connectors reduces the collection blast radius.[0][6]
- Treat unexpected links that open an AI assistant with a pre-populated prompt as potentially malicious and warn users accordingly.: The attack begins when a victim opens a crafted Copilot deep link that auto-executes an injected prompt without further interaction.[0][6]
- Include AI memory, personalization, connectors, and conversation history within incident-response scope, and inspect memory for injected instructions before remediation.: Memory poisoning persists through password changes, session revocation, and device re-enrollment, so identity-containment steps alone will not remove malicious retained instructions.[0][6]
- Monitor AI-mediated outbound requests to new, rare, or unapproved external destinations, including long or high-entropy encoded query strings following connected-app access.: Exfiltration can flow through Copilot's legitimate URL-fetch function using Base64-encoded data, reducing visibility for controls that assume the traffic is ordinary Copilot browsing.[0]