Aug 21
/
Latest News
Researchers Reveal CoSnitch: One‑Click Copilot Flaw Enabling Silent Data Theft
Varonis Threat Labs has disclosed a critical one‑click vulnerability in Microsoft Copilot Personal that allowed attackers to silently extract sensitive data from enterprise environments. The flaw, named CoSnitch and tracked as CVE‑2026‑24301, was patched by Microsoft on August 18, 2026.
Researchers said CoSnitch stood out because Copilot itself revealed the underlying weakness. During routine use, the AI surfaced internal behaviors and undocumented parameters, enabling what Varonis calls “meta‑hacking” — a technique that uses an AI assistant’s own reasoning to map its architecture and expose attack paths.
According to Varonis, a crafted URL containing specific parameters could trigger Copilot to automatically execute attacker‑supplied prompts the moment the page loaded. Once activated, Copilot operated with full access to the victim’s authenticated session, including connected apps such as Gmail, Google Drive, Calendar, OneDrive, and Copilot’s persistent memory.
The flaw enabled attackers to retrieve full email bodies, calendar details, file metadata, chat history, and saved memory entries. Copilot could then encode the stolen data and send it to an attacker‑controlled server using its built‑in URL‑fetching capability — a request indistinguishable from legitimate web‑summarization traffic.
Varonis also identified a second issue that allowed attackers to modify a user’s persistent Copilot memory through indirect prompt injection. By asking Copilot to summarize a malicious webpage, hidden instructions embedded in the page were ingested and written into the user’s memory, persisting across sessions, password resets, and device re‑enrollment.
CoSnitch is the third Copilot flaw Varonis has reported this year, following Reprompt and SearchLeak, both of which also enabled one‑click exploitation. The company said it has seen no evidence of in‑the‑wild attacks and credited Microsoft for its collaboration during disclosure.
Researchers warn that the incident highlights a broader challenge: AI assistants now sit at the center of enterprise ecosystems, with wide access to email, files, calendars, and internal systems. Attack chains that exploit AI reasoning rather than traditional software bugs may become increasingly common as organizations deepen their reliance on AI‑driven workflows.
Researchers said CoSnitch stood out because Copilot itself revealed the underlying weakness. During routine use, the AI surfaced internal behaviors and undocumented parameters, enabling what Varonis calls “meta‑hacking” — a technique that uses an AI assistant’s own reasoning to map its architecture and expose attack paths.
According to Varonis, a crafted URL containing specific parameters could trigger Copilot to automatically execute attacker‑supplied prompts the moment the page loaded. Once activated, Copilot operated with full access to the victim’s authenticated session, including connected apps such as Gmail, Google Drive, Calendar, OneDrive, and Copilot’s persistent memory.
The flaw enabled attackers to retrieve full email bodies, calendar details, file metadata, chat history, and saved memory entries. Copilot could then encode the stolen data and send it to an attacker‑controlled server using its built‑in URL‑fetching capability — a request indistinguishable from legitimate web‑summarization traffic.
Varonis also identified a second issue that allowed attackers to modify a user’s persistent Copilot memory through indirect prompt injection. By asking Copilot to summarize a malicious webpage, hidden instructions embedded in the page were ingested and written into the user’s memory, persisting across sessions, password resets, and device re‑enrollment.
CoSnitch is the third Copilot flaw Varonis has reported this year, following Reprompt and SearchLeak, both of which also enabled one‑click exploitation. The company said it has seen no evidence of in‑the‑wild attacks and credited Microsoft for its collaboration during disclosure.
Researchers warn that the incident highlights a broader challenge: AI assistants now sit at the center of enterprise ecosystems, with wide access to email, files, calendars, and internal systems. Attack chains that exploit AI reasoning rather than traditional software bugs may become increasingly common as organizations deepen their reliance on AI‑driven workflows.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.