Varonis Threat Labs disclosed CoSnitch, a chained attack against Microsoft Copilot Personal that could trigger prompt execution from a malicious link, exfiltrate data from connected services, and poison the assistant’s persistent memory. Researchers said the chain combined three issues: an undocumented autorun=1 URL parameter that executed prompts on page load in an authenticated session, abuse of Copilot’s URL-fetching and connected OAuth data sources to pull information from services such as Gmail, Google Drive, Google Calendar, and Copilot chat history, and indirect prompt injection through web summarization that could write attacker instructions into memory.
The researchers said they uncovered parts of the attack path by repeatedly questioning Copilot about failed prompt auto-execution attempts, eliciting details about its own security controls and hidden parameters without reverse engineering. Varonis reported the issue to Microsoft in December 2025, and Microsoft shipped patches on August 18, 2026; one report said CVE assignment was also being prepared. Varonis said it found no evidence of exploitation in the wild, but warned the flaw reflects a broader weakness in AI assistants that can treat untrusted content as executable instructions while operating with the user’s authorized access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft shipped patches for the CoSnitch issues on August 18, 2026, according to Varonis. Varonis said it had seen no evidence that the attack chain was exploited in the wild.
After Varonis reported CoSnitch, Microsoft implemented initial protective measures in February 2026 before releasing full fixes later in August. This represents an intermediate remediation step for the Copilot Personal vulnerability chain.
Varonis Threat Labs disclosed the CoSnitch vulnerability chain to Microsoft in December 2025. The issue involved prompt auto-execution, data exfiltration through connected services, and persistent memory poisoning in Microsoft Copilot Personal.
Varonis Threat Labs publicly disclosed CoSnitch, a chained attack against Microsoft Copilot Personal that used an undocumented autorun URL parameter, connected OAuth data sources, and web summarization-based prompt injection. The researchers said they uncovered the chain through a technique they called meta-hacking, in which Copilot revealed architectural details through iterative questioning.
Microsoft assigned CVE-2026-24301 to the CoSnitch issue, classifying it as an information disclosure vulnerability affecting Copilot Personal and rating it 8.8 under CVSS 3.1. The company said enterprise customers were unaffected and no customer action was required after the fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcexakep.ru
Open sourcecysecurity.news
Open sourcecyberupdates365.com
Open sourcethehackernews.com
Open sourcevaronis.com
Open sourcetheregister.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.