Critical Microsoft Copilot CoSnitch Flaw Lets Attackers Steal Sensitive Data
Key Takeaways A critical vulnerability, dubbed CoSnitch (CVE-2026-24301), in Microsoft Copilot Personal allowed attackers to exfiltrate sensitive user data from connected accounts. The exploit...
Key Takeaways
- A critical vulnerability, dubbed CoSnitch (CVE-2026-24301), in Microsoft Copilot Personal allowed attackers to exfiltrate sensitive user data from connected accounts.
- The exploit required only a single click on a malicious link, triggering an automatic prompt execution, data retrieval from linked applications, and covert exfiltration.
- Discovered by Varonis Threat Labs, the flaw was patched by Microsoft on August 18, 2026.
- The discovery method, termed “meta-hacking,” involved social engineering the AI’s reasoning process to uncover undocumented functionalities.
A severe vulnerability within Microsoft Copilot Personal, identified as CVE-2026-24301 and named CoSnitch, enabled threat actors to surreptitiously extract confidential information from a victim’s connected services. This sophisticated attack could be initiated with just a single click on a specially crafted malicious link.
Table Of Content
The flaw, brought to light by Varonis Threat Labs, has since been addressed by Microsoft, with a patch released on August 18, 2026. However, the unique methodology employed in its discovery holds significant implications for the future of AI security research.
CoSnitch represents the third Copilot-related vulnerability that Varonis has identified this year. Prior discoveries include Reprompt, which bypassed Copilot’s integrated safety protocols through repeated questioning, and SearchLeak, which transformed Microsoft 365 Copilot Enterprise into an unauthorized data exfiltration channel.
A common characteristic across all three vulnerabilities is the simplicity of their trigger: a single click on an seemingly innocuous link. This action initiates the attack chain without providing any discernible warnings to the victim or their security infrastructure.
Microsoft Copilot CoSnitch Vulnerability
The CoSnitch vulnerability was not a singular defect but rather a sequence of three distinct weaknesses that attackers could chain together. The initial component involved an undocumented URL parameter, which, when combined with Copilot’s standard “?q=” query parameter, facilitated the automatic execution of an attacker-defined prompt. This execution occurred immediately upon the victim’s browser loading the page, requiring no user interaction such as a click or keystroke.
Once the malicious prompt was executed, Copilot could then query applications linked to the victim’s account, including services like Gmail, Google Drive, and Calendar. The retrieved data was then silently transmitted to an attacker-controlled server, leveraging Copilot’s own native URL-fetching capabilities.
The exfiltrated data underwent base64 encoding and was sent as a standard outbound web request. This made the data transfer indistinguishable from Copilot’s regular browsing activities, effectively bypassing conventional security monitoring tools that would typically flag unusual data movement.
Perhaps the most concerning aspect of the CoSnitch vulnerability was a third weakness: the ability for a booby-trapped webpage to inject hidden instructions directly into Copilot’s persistent memory during summarization. This “poisoned” memory remained intact even after standard security measures like password changes, session revocations, and device re-enrollments, rendering typical incident response procedures ineffective against its persistence.
Meta-Hacking: A New Approach to AI Vulnerability Discovery
What truly distinguishes this discovery is the innovative technique Varonis employed to uncover it. Rather than traditional reverse-engineering of code, researchers engaged Copilot in a dialogue, repeatedly querying why automatic execution “wasn’t possible.” Each refusal or explanation provided by the AI was then reframed as a subsequent question.
Copilot’s own responses, intended to demonstrate the impossibility of the exploit, inadvertently revealed critical details about its internal architecture. Ultimately, these interactions exposed the precise undocumented parameter necessary to execute the attack. Varonis has termed this methodology “meta-hacking,” characterizing it as a form of social engineering directed at the AI’s reasoning processes, rather than a direct assault on its underlying code.
Varonis reported CoSnitch to Microsoft in December 2025. Microsoft has stated that there is no evidence of active exploitation of this vulnerability prior to the patch being deployed.
Nevertheless, this incident highlights a growing concern: as AI copilots gain increasingly deep access to sensitive organizational data—including emails, files, calendars, and chat histories—a single compromised link could facilitate the large-scale exfiltration of confidential information, all while appearing as routine AI assistant activity.
What You Should Do
- Regularly audit and review which third-party applications are connected to AI copilots.
- Treat AI assistants as privileged insiders, applying the same rigorous access oversight and monitoring protocols as for human employees.
- Verify that existing security monitoring tools are capable of detecting anomalous data access and exfiltration originating from AI assistants, addressing potential blind spots.
- Ensure all Microsoft Copilot Personal instances are updated to the latest patched version.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.