Microsoft Copilot Personal Vulnerabilities Allow One-Click Data Exfiltration from Connected Apps

Published:

spot_img

Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could enable attackers to extract data from connected applications with a single click on a malicious link. This issue was reported to Microsoft in December 2025, with patches released on August 18, 2026.

The vulnerabilities exploit an undocumented URL parameter that was revealed during testing. According to Varonis, the parameter, autorun=1, when combined with another parameter, allows an attacker-supplied prompt to execute automatically within the victim’s authenticated session. This means that sensitive information could be pulled from connected services without user interaction.

Varonis stated that there is no evidence of the CoSnitch vulnerabilities being exploited in the wild. The researchers discovered the parameter through a method they refer to as meta-hacking, where they repeatedly queried Copilot about executing prompts without user interaction. The assistant eventually disclosed the parameter, which led to the vulnerabilities being exploited.

Details of the Vulnerabilities

The CoSnitch vulnerabilities consist of three main components:

  • Automatic prompt execution: The combination of the two parameters allows an attacker to run a prompt automatically upon page load, mimicking user input.
  • Exfiltration through connected services: The injected prompt can access data from services the user has authorized, encode it, and send it to an attacker-controlled location.
  • Persistent memory writes: A crafted web page can cause Copilot to write attacker instructions into the user’s memory store, affecting future sessions.

In testing, the researchers noted that Copilot could return sensitive information such as email metadata, calendar details, and file summaries from connected services like Google Drive. Varonis emphasized that the exfiltration requests appear similar to legitimate requests made by Copilot, making them difficult to detect.

Microsoft’s documentation states that users must authorize services for Copilot to access them, and the assistant operates within the permissions already granted to the user. Varonis has advised users to review their connected applications and exercise caution when interacting with links that could open AI assistants.

For further details, refer to the advisory published by The Hacker News.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

Cleopatra Hospitals Group Cuts Cyber-Incident Investigation Times by 75% with Kaspersky Solution

Cleopatra Hospitals Group (CHG), the largest private healthcare network in Egypt, has successfully reduced its investigation times for high-severity cyber incidents from eight hours...

Microsoft Identifies MacSync Stealer’s Evolving Infrastructure and Data Exfiltration Techniques

Microsoft Defender Experts have identified the MacSync Stealer, a macOS-focused information stealer that utilizes evolving infrastructure for payload delivery, communication with compromised devices, and...

Q2 2026 Report Reveals Surge in Vulnerability Disclosures and Evolving Threat Landscape

The cybersecurity landscape is undergoing significant changes, as highlighted in the latest Quarterly Threat Landscape Report from Rapid7 Labs. The report reveals a dramatic...

Google’s Agentic Vulnerability Discovery Harness Enhances AI Security Against Exploits

Enhancing AI Security: The Role of Google's Agentic Vulnerability Discovery Harness The rise of adversarial AI has intensified the threat landscape, particularly concerning data theft...