Exploits

Microsoft Copilot CoSnitch Vulnerabilities Enable Data Theft

Published  ·  6 min read

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal. A single click on a crafted link could silently pull data from connected apps and other information available to the victim's Copilot session.

The researchers collectively named the flaws CoSnitch. The vulnerabilities turn in part on an undocumented URL parameter that the assistant itself surfaced during testing.

Varonis reported the issue to Microsoft in December 2025. Patches shipped on August 18, 2026.

Let me walk you through the Microsoft Copilot CoSnitch vulnerabilities and what they mean for users.

Key Points About CoSnitch

  • CoSnitch affects Microsoft Copilot Personal (copilot.microsoft.com)
  • One click on a crafted link can exfiltrate data
  • The flaw uses an undocumented autorun=1 parameter
  • Data from connected apps can be stolen
  • A separate memory poisoning vulnerability exists
  • Patched by Microsoft on August 18, 2026
  • No evidence of exploitation in the wild

How the Flaw Was Found

The Microsoft Copilot CoSnitch vulnerabilities were discovered through an unusual method. The researchers repeatedly asked Copilot why a prompt couldn't be made to run without user interaction. They call this approach "meta-hacking."

Each refusal carried a technical justification. The assistant eventually named a parameter: autorun=1. It also described the session conditions under which it worked and the protections that were supposed to have disabled it.

When the researchers built the URL exactly as described, the parameter Copilot had said no longer worked executed. Varonis said: "Copilot wasn't breached; it was played."

The Three Vulnerabilities

The Microsoft Copilot CoSnitch vulnerabilities are grouped into three issues:

1. Automatic Prompt Execution

The autorun=1 and q parameters together cause an attacker-supplied prompt to run on page load. This happens inside the victim's authenticated session. The prompt has the same capabilities as an instruction the user typed.

2. Exfiltration Through Connected Services

The injected prompt can query services the user has already authorized. It can also encode the retrieved data and use the URL fetching capabilities of Copilot's integrated webhook service. The technique doesn't grant Copilot new permissions or expand the user's existing access.

3. Persistent Memory Writes

A crafted web page, when summarized by Copilot, can cause the assistant to write attacker instructions into the user's memory store. These instructions can shape later sessions.

What Data Was Exposed

In testing, the Microsoft Copilot CoSnitch vulnerabilities allowed access to:

  • Message bodies, subject lines, and sender/recipient metadata from connected mail accounts
  • Calendar titles, attendees, times, and locations
  • File names and metadata summaries from Google Drive
  • Full prior conversation content from chat history
  • Saved instructions and user-defined rules held in the memory store

The exfiltration request is indistinguishable from ordinary Copilot fetches. Base64 encoding can help avoid filters scanning outbound requests for sensitive patterns.

The Memory Poisoning Issue

The Microsoft Copilot CoSnitch vulnerabilities include a separate memory path. An injected instruction survives password changes, session revocation, and device re-enrollment. It stays active in later conversations until the user deletes it from Copilot's memory settings.

The memory write produces no process, file, network connection, or log entry that security tooling would flag. The only visible change is in Copilot's memory interface.

Previous Research

The web summarization path isn't the first time Copilot memory has been reported to Microsoft. Researcher Håkon Måløy documented an attacker-controlled page that persisted unintended memory when a victim used a Microsoft 365 Copilot summarization flow. He published on June 22, 2026, after a 90-day coordination period. Microsoft's status was "mitigated globally."

Johann Rehberger separately reported memory writes and deletions through indirect prompt injection in Microsoft 365 Copilot. He also reported memory modification in the consumer assistant in research associated with CVE-2026-24299.

Microsoft's Position

Microsoft set out its own position on the same class of attack in a June 22 security blog post. The company credited MSRC cases from Rehberger, Måløy, and Gal Zror.

Key Points from Microsoft:

  • Memories pass through sanitization and prompt-injection checks on write
  • M365 Copilot runs Task Adherence checks on every explicit memory write
  • Memory updates are recorded to organizational audit logs

Updates are surfaced to analysts through a MemoryUpdated field in Defender Advanced Hunting and Sentinel

What Users Should Do

The Microsoft Copilot CoSnitch vulnerabilities have been patched. But there are still steps users should take:

Review Connected Apps:

  • Check which apps are connected to Copilot
  • Disconnect those not actively needed
  • Limit the data Copilot can access

Treat Copilot as a Privileged Insider:

  • Review access permissions regularly
  • Monitor for anomalies
  • Exercise caution with links that open AI assistants

Check Memory Store:

  • Review saved memory entries
  • Delete any suspicious instructions

The disclosure doesn't state whether Microsoft removed entries created before the fix

The Connection to RovoBlast

The Microsoft Copilot CoSnitch vulnerabilities disclosure comes less than two weeks after Varonis detailed RovoBlast. That was a one-click attack on Atlassian's Rovo assistant. It abused the rovoChatPrompt URL parameter to seed attacker-controlled instructions into a signed-in user's session.

Varonis said Atlassian fixed the issue before its public disclosure.

Wrapping It Up

The Microsoft Copilot CoSnitch vulnerabilities are a serious reminder that AI assistants can be manipulated. A single click on a crafted link could silently exfiltrate data from connected apps.

Key points to remember:

  • CoSnitch allows one-click data exfiltration
  • Uses the autorun=1 parameter
  • Affects Copilot Personal (copilot.microsoft.com)
  • Patched on August 18, 2026
  • Separate memory poisoning vulnerability exists
  • No evidence of exploitation in the wild

Users should review which apps are connected to Copilot. Disconnect all that is not being used at the moment. Move cautiously while clicking on links through the AI assistant.

Microsoft Copilot CoSnitch vulnerabilities are one such case where AI assistants are both extremely powerful as well as potentially dangerous. Stay informed. Stay secure.

FAQ Section

What are the Microsoft Copilot CoSnitch vulnerabilities?

CoSnitch is a set of three vulnerabilities in Microsoft Copilot Personal. They allow one-click data exfiltration via crafted links and persistent memory poisoning.

How does the attack work?

The crafted link using autorun=1 and q parameters makes an attacker-controlled prompt run automatically. The prompt requests information from any connected applications and extracts that data.

What data can be stolen?

The content of emails, information in the calendar, metadata of files stored in Google Drive, history of the conversations and memory instructions can all be exfiltrated.

Does there exist a patch for this vulnerability?

Yes, Microsoft patched this vulnerability on August 18, 2026. Make sure to run the latest version.

What should users do?

Examine the associated apps, disconnect any apps which are not required and be careful while clicking on links that open AI assistants. Check out Copilot's memory store for suspicious entries.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067