Vulnerabilities in Microsoft Copilot Personal Enable Data Exfiltration

Recent findings reveal vulnerabilities in Microsoft Copilot Personal that could allow unauthorized data access through a single click.

Recent research from Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal that could enable attackers to exfiltrate data from connected applications with a single click on a crafted link. These vulnerabilities, collectively referred to as CoSnitch, exploit an undocumented URL parameter that surfaced during testing.

Details of the Vulnerabilities

Varonis reported the vulnerabilities to Microsoft in December 2025, with patches released on August 18, 2026. The primary vulnerability, tracked as CVE-2026-24301, affects the consumer assistant available at copilot.microsoft.com. Notably, the research does not indicate that similar vulnerabilities exist in Microsoft 365 Copilot.

Mechanics of the Attack

The researchers utilized a method they termed meta-hacking, repeatedly querying Copilot about executing prompts without user interaction. This led to the discovery of a parameter, autorun=1, which, when paired with another parameter, q, allowed an attacker-supplied prompt to execute automatically upon page load within the victim’s authenticated session.

The attack can lead to two main outcomes: first, the injected prompt can query services the user has authorized and send the retrieved data to an attacker-controlled webhook. Second, a crafted web page can cause Copilot to write instructions into the user’s memory store, which can persist across sessions.

Potential Impact and Evidence of Exploitation

During testing, the researchers noted that Copilot could return sensitive information, including email metadata, calendar details, and file information from Google Drive. However, Varonis stated that there is currently no evidence that the CoSnitch vulnerabilities have been exploited in the wild.

Microsoft’s documentation indicates that users must authorize services for Copilot to access them, and the vulnerabilities do not expand the permissions granted to Copilot. However, the exfiltration requests may appear similar to legitimate requests made by Copilot during normal operations.

Recommendations and Mitigations

Varonis recommends that users review the applications connected to Copilot and disconnect any that are not actively needed. They advise treating Copilot as a privileged insider for access review and anomaly detection. Notably, the company did not specify any client updates that users need to install to mitigate these vulnerabilities.

Additionally, the report raises questions about whether Microsoft’s remediation efforts retroactively address memory entries created before the fix was implemented.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 353