CVE Tools

'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture

Dark ReadingBy Alexander Culafi

ResearchMicrosoft Copilot Personal

Our summary

Varonis Threat Labs disclosed a series of vulnerabilities in Microsoft Copilot Personal, collectively dubbed "CoSnitch," which enable threat actors to extract internal architectural details and exfiltrate sensitive data. The attack chain relies on a technique called "meta-hacking" to map the system's behavior, followed by the use of specially crafted URLs containing an undocumented ?autorun=1 parameter to trigger automatic prompt execution within a victim's authenticated session. This allows attackers to access connected services such as Gmail and Google Drive without further user interaction. Microsoft assigned the flaw as CVE-2026-24301, rating it 8.8 on CVSS 3.1, and deployed a patch on August 18, 2025. While enterprise customers are reportedly unaffected and no in-the-wild exploitation has been observed, researchers warn that personal instances linked to corporate accounts pose a significant risk.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store