Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
ResearchMicrosoft Copilot PersonalOur summary
Varonis Threat Labs identified three vulnerabilities, dubbed CoSnitch, in Microsoft Copilot Personal that permit attackers to silently extract data from connected services through a single malicious link click. The flaws, tracked as CVE-2026-24301, exploit an undocumented URL parameter to execute prompts within the victim's authenticated session without user interaction. Although no evidence of real-world exploitation was found, the issue allowed access to emails, calendar entries, and file metadata linked to the user's account. Microsoft deployed patches on August 18, 2026, addressing these issues which included the ability to persistently inject instructions into the assistant's memory store.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.