Microsoft Copilot Personal Vulnerabilities Allow One-Click Data Exfiltration from Connected Apps

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could enable attackers to extract data from connected applications with a single click on a malicious link. This issue was reported to Microsoft in December 2025, with patches released on August 18, 2026.

The vulnerabilities exploit an undocumented URL parameter that was revealed during testing. According to Varonis, the parameter, autorun=1, when combined with another parameter, allows an attacker-supplied prompt to execute automatically within the victim’s authenticated session. This means that sensitive information could be pulled from connected services without user interaction.

Varonis stated that there is no evidence of the CoSnitch vulnerabilities being exploited in the wild. The researchers discovered the parameter through a method they refer to as meta-hacking, where they repeatedly queried Copilot about executing prompts without user interaction. The assistant eventually disclosed the parameter, which led to the vulnerabilities being exploited.

Details of the Vulnerabilities

The CoSnitch vulnerabilities consist of three main components:

  • Automatic prompt execution: The combination of the two parameters allows an attacker to run a prompt automatically upon page load, mimicking user input.
  • Exfiltration through connected services: The injected prompt can access data from services the user has authorized, encode it, and send it to an attacker-controlled location.
  • Persistent memory writes: A crafted web page can cause Copilot to write attacker instructions into the user’s memory store, affecting future sessions.

In testing, the researchers noted that Copilot could return sensitive information such as email metadata, calendar details, and file summaries from connected services like Google Drive. Varonis emphasized that the exfiltration requests appear similar to legitimate requests made by Copilot, making them difficult to detect.

Microsoft’s documentation states that users must authorize services for Copilot to access them, and the assistant operates within the permissions already granted to the user. Varonis has advised users to review their connected applications and exercise caution when interacting with links that could open AI assistants.

For further details, refer to the advisory published by The Hacker News.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...