{"id":144539,"date":"2026-08-19T06:36:14","date_gmt":"2026-08-19T06:36:14","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/144539\/"},"modified":"2026-08-19T06:36:14","modified_gmt":"2026-08-19T06:36:14","slug":"critical-microsoft-copilot-cosnitch-flaw-lets-hackers-steal-sensitive-data-with-one-click","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/144539\/","title":{"rendered":"Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click"},"content":{"rendered":"<p class=\"wp-block-paragraph\">A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. <\/p>\n<p class=\"wp-block-paragraph\">This flaw could enable an attacker to <a href=\"https:\/\/gbhackers.com\/microsoft-copilot-word-flaw\/\" data-type=\"post\" data-id=\"193979\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">trigger malicious Copilot prompts<\/a>, access data from connected OAuth applications, and silently transmit that information to an attacker-controlled server.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft addressed this issue on August 18, 2026, following Varonis\u2019s responsible disclosure in December 2025. According to Varonis, there is currently no evidence of exploitation in the wild.<\/p>\n<p>Microsoft Copilot CoSnitch Flaw<\/p>\n<p class=\"wp-block-paragraph\">CoSnitch highlights the risks associated with an AI assistant having broad access to a user\u2019s email, cloud files, calendar, chat history, and persistent memory. <\/p>\n<p class=\"wp-block-paragraph\">Instead of exploiting a traditional software bug in applications like Gmail or Google Drive, the attack leverages Copilot\u2019s ability to perform legitimate actions on behalf of an authenticated user.<\/p>\n<p class=\"wp-block-paragraph\">The attack commences when a victim opens a specially crafted Copilot link delivered through phishing emails, chat messages, malicious web pages, or QR codes. <\/p>\n<p class=\"wp-block-paragraph\">Researchers discovered that an undocumented URL parameter could cause a provided prompt to execute as the Copilot page loaded, bypassing the normal requirement for a user to submit the request manually.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/CoSnitch-2-final.webp\" alt=\"Copilot extracting email body content, including plaintext credentials from connected Gmail (Source: Varonis)\"\/>Copilot extracting email body content, including plaintext credentials from connected Gmail (Source: Varonis)<\/p>\n<p class=\"wp-block-paragraph\">Once activated, the prompt inherits the victim\u2019s authenticated Copilot session and the permissions granted to the connectors. It can then instruct Copilot to search linked services, retrieve relevant content, and send the results to an external endpoint using its built-in web-fetching or URL-summarization functionality.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.varonis.com\/blog\/cosnitch\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Varonis\u2019s research demonstrated<\/a> the ability to access data from connected Gmail or Outlook accounts, Google Calendar, Google Drive, Copilot chat history, and the assistant\u2019s persistent memory. Potentially exposed information includes email content, sender and recipient details, meeting information, file metadata, saved user preferences, and previous chat data.<\/p>\n<p class=\"wp-block-paragraph\">The exfiltration technique relied on Copilot\u2019s routine capability to retrieve and summarize external URLs. A malicious prompt could gather data into the model\u2019s active context, encode it for URL transport, and instruct Copilot to request an attacker-controlled URL containing the encoded information.<\/p>\n<p class=\"wp-block-paragraph\">From a network monitoring perspective, this outbound request could resemble a standard HTTPS fetch that Copilot typically performs during normal web summarization. This reduces visibility for traditional security controls that focus on identifying suspicious processes, unusual ports, or anomalous network destinations.<\/p>\n<p class=\"wp-block-paragraph\">The key security failure was not unauthorized OAuth access; rather, the victim had already granted Copilot access to the connected application. CoSnitch removed the expectation that connector actions would occur only in response to an intentional user request.<\/p>\n<p class=\"wp-block-paragraph\">The third component involved indirect prompt injection via web summarization. An attacker could host a seemingly benign webpage with concealed instructions embedded in HTML comments, metadata, or visually hidden elements.<\/p>\n<p class=\"wp-block-paragraph\">When a victim asked Copilot to summarize that page, the service would retrieve the entire content and process both the visible text and the hidden attacker-controlled instructions. Varonis found that this could cause Copilot to write malicious instructions into the user\u2019s persistent memory.<\/p>\n<p class=\"wp-block-paragraph\">This memory poisoning presents a significant long-term risk, as injected instructions may remain active across future sessions until manually removed. A compromised memory entry could alter Copilot\u2019s responses, suppress warnings, distort summaries, or trigger future actions based on attacker-defined conditions.<\/p>\n<p class=\"wp-block-paragraph\">Unlike traditional endpoint malware, this persistence mechanism exists within the AI assistant\u2019s user context. Password resets, session revocations, or device re-enrollment may not eliminate a poisoned memory record.<\/p>\n<p class=\"wp-block-paragraph\">Varonis described its discovery process as \u201cmeta-hacking.\u201d Researchers prompted Copilot to explain why automatic execution should not be possible. <\/p>\n<p class=\"wp-block-paragraph\">Then they used its technical explanations to narrow the attack surface. They stated that Copilot disclosed implementation details regarding URL behavior and historical protections while outlining its limitations.<\/p>\n<p class=\"wp-block-paragraph\">CoSnitch is the third flaw in Microsoft Copilot reported by Varonis this year,<a href=\"https:\/\/gbhackers.com\/microsoft-365-copilot-vulnerability-2\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> following Reprompt and SearchLeak<\/a>. Together, these findings emphasize how AI platforms can centralize access to valuable enterprise data behind a single conversational interface.<\/p>\n<p class=\"wp-block-paragraph\">Organizations should implement Microsoft\u2019s security updates, review Copilot connector permissions, restrict unnecessary third-party integrations, monitor AI-related outbound requests, and educate employees on the risks of links that open AI assistants with pre-populated instructions.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\">Stop new phishing &amp; malware before they compromise your business.\u00a0<a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn&amp;utm_medium=link+placement&amp;utm_campaign=stop+new+phishing&amp;utm_content=ti+feeds+sales&amp;utm_term=050826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Integrate live intel from 15K SOCs around the world<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable&hellip;\n","protected":false},"author":2,"featured_media":144540,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7853,416,1393,9644,320,7852,10718],"class_list":["post-144539","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-copilot","tag-copilot","tag-cyber-security","tag-cyber-security-news","tag-microsoft","tag-microsoft-copilot","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/144539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=144539"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/144539\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/144540"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=144539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=144539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=144539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}