Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
ID: 3ae1a716-fcf6-5968-8dcc-f9e4098ff2fc
STIX ID: report--3ae1a716-fcf6-5968-8dcc-f9e4098ff2fc
Feed Name: The Hacker News
Varonis disclosed three vulnerabilities called “CoSnitch” in Microsoft Copilot Personal that allowed a crafted one-click URL (using an undocumented autorun=1 parameter combined with q) to execute attacker-supplied prompts in a victim’s authenticated session, exfiltrate data from connected services via Copilot’s URL fetch, and write persistent malicious entries into Copilot’s memory store. Varonis reported the issues to Microsoft (patches released 18 Aug 2026), found no evidence of active exploitation, and recommended reviewing connected apps, treating Copilot as a privileged insider, and exercising caution with links that open AI assistants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
