CVE Tools

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

The Hacker NewsBy The Hacker News

ResearchMicrosoft Copilot Personal

Our summary

Varonis Threat Labs identified three vulnerabilities, dubbed CoSnitch, in Microsoft Copilot Personal that permit attackers to silently extract data from connected services through a single malicious link click. The flaws, tracked as CVE-2026-24301, exploit an undocumented URL parameter to execute prompts within the victim's authenticated session without user interaction. Although no evidence of real-world exploitation was found, the issue allowed access to emails, calendar entries, and file metadata linked to the user's account. Microsoft deployed patches on August 18, 2026, addressing these issues which included the ability to persistently inject instructions into the assistant's memory store.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store