'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
ID: f9d537a3-f898-5d5a-b736-61fb0e667bbf
STIX ID: report--f9d537a3-f898-5d5a-b736-61fb0e667bbf
Feed Name: Dark Reading
Threat Score
Varonis Threat Labs disclosed 'CoSnitch,' a chain of vulnerabilities in Microsoft Copilot Personal that allowed attackers to craft URLs (using an undocumented autorun parameter) to auto-execute prompts in a victim's authenticated session, enabling information disclosure, data exfiltration from connected services, persistent memory poisoning, and other malicious actions; Microsoft patched the issue (CVE-2026-24301, CVSS 8.8) and reported no observed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
