Microsoft Copilot Personal Vulnerabilities Allow One-Click Data Exfiltration from Connected Apps

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could enable attackers to extract data from connected applications with a single click on a malicious link. This issue was reported to Microsoft in December 2025, with patches released on August 18, 2026.

The vulnerabilities exploit an undocumented URL parameter that was revealed during testing. According to Varonis, the parameter, autorun=1, when combined with another parameter, allows an attacker-supplied prompt to execute automatically within the victim’s authenticated session. This means that sensitive information could be pulled from connected services without user interaction.

Varonis stated that there is no evidence of the CoSnitch vulnerabilities being exploited in the wild. The researchers discovered the parameter through a method they refer to as meta-hacking, where they repeatedly queried Copilot about executing prompts without user interaction. The assistant eventually disclosed the parameter, which led to the vulnerabilities being exploited.

Details of the Vulnerabilities

The CoSnitch vulnerabilities consist of three main components:

  • Automatic prompt execution: The combination of the two parameters allows an attacker to run a prompt automatically upon page load, mimicking user input.
  • Exfiltration through connected services: The injected prompt can access data from services the user has authorized, encode it, and send it to an attacker-controlled location.
  • Persistent memory writes: A crafted web page can cause Copilot to write attacker instructions into the user’s memory store, affecting future sessions.

In testing, the researchers noted that Copilot could return sensitive information such as email metadata, calendar details, and file summaries from connected services like Google Drive. Varonis emphasized that the exfiltration requests appear similar to legitimate requests made by Copilot, making them difficult to detect.

Microsoft’s documentation states that users must authorize services for Copilot to access them, and the assistant operates within the permissions already granted to the user. Varonis has advised users to review their connected applications and exercise caution when interacting with links that could open AI assistants.

For further details, refer to the advisory published by The Hacker News.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the...

Seclore Enhances Data-Centric Security Solutions Across Middle East, Turkey, and Africa

Seclore Expands Data-Centric Security Solutions Across META Seclore has unveiled significant advancements in its data-centric security solutions during GISEC Global 2026, focusing on the Middle...

AI’s Impact on Cybersecurity: Microsoft Highlights Evolving Threats and Security Fundamentals

The integration of artificial intelligence (AI) into cybersecurity has fundamentally altered the threat landscape, presenting both new challenges and opportunities for organizations. As cyberattackers...

Cochin Shipyard lays keel for Indian Navy’s first Next Generation Missile Vessel

The keel laying ceremony of the first Next Generation Missile Vessel (NGMV) for the Indian Navy was held on September 18, 2026. This milestone...