Varonis Threat Labs has recently unveiled three significant vulnerabilities in Microsoft Copilot Personal, collectively known as CoSnitch. These flaws allow a single click on a crafted link to extract data from connected applications without user interaction. The vulnerabilities are tied to an undocumented URL parameter, which was inadvertently revealed by Copilot during testing. Upon reporting the issue to Microsoft in December 2025, patches were released on August 18, 2026, to address the problem.
CoSnitch, identified as CVE-2026-24301 in Microsoft's Security Update Guide, affects the consumer assistant hosted at copilot.microsoft.com. There is no indication that Microsoft 365 Copilot is impacted. Varonis researchers used a technique called meta-hacking to discover the parameter autorun=1, which when used alongside the q parameter, initiates a prompt without user action. This vulnerability enables the exfiltration of sensitive data such as email metadata, calendar details, and file summaries from connected services.
Varonis confirmed that the exfiltration request is indistinguishable from normal Copilot operations, making it challenging to detect. Additionally, memory-related vulnerabilities allow injected instructions to persist through security measures like password changes and session revocations. These vulnerabilities have been addressed in recent updates, although it remains unclear if previous memory entries were retroactively removed.
Microsoft emphasizes that users must authorize services for Copilot access and that it operates within the user's existing permissions. The company has implemented memory sanitization and prompt-injection checks for Microsoft 365 Copilot to mitigate similar threats. Varonis recommends that users review connected apps, treat the assistant as a privileged insider, and exercise caution with links that trigger AI assistants.


