Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could enable attackers to extract data from connected applications with a single click on a malicious link. This issue was reported to Microsoft in December 2025, with patches released on August 18, 2026.
The vulnerabilities exploit an undocumented URL parameter that was revealed during testing. According to Varonis, the parameter, autorun=1, when combined with another parameter, allows an attacker-supplied prompt to execute automatically within the victim’s authenticated session. This means that sensitive information could be pulled from connected services without user interaction.
Varonis stated that there is no evidence of the CoSnitch vulnerabilities being exploited in the wild. The researchers discovered the parameter through a method they refer to as meta-hacking, where they repeatedly queried Copilot about executing prompts without user interaction. The assistant eventually disclosed the parameter, which led to the vulnerabilities being exploited.
Details of the Vulnerabilities
The CoSnitch vulnerabilities consist of three main components:
- Automatic prompt execution: The combination of the two parameters allows an attacker to run a prompt automatically upon page load, mimicking user input.
- Exfiltration through connected services: The injected prompt can access data from services the user has authorized, encode it, and send it to an attacker-controlled location.
- Persistent memory writes: A crafted web page can cause Copilot to write attacker instructions into the user’s memory store, affecting future sessions.
In testing, the researchers noted that Copilot could return sensitive information such as email metadata, calendar details, and file summaries from connected services like Google Drive. Varonis emphasized that the exfiltration requests appear similar to legitimate requests made by Copilot, making them difficult to detect.
Microsoft’s documentation states that users must authorize services for Copilot to access them, and the assistant operates within the permissions already granted to the user. Varonis has advised users to review their connected applications and exercise caution when interacting with links that could open AI assistants.
For further details, refer to the advisory published by The Hacker News.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


