Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced during testing. The company said it reported the issue to Microsoft in December 2025 and that patches shipped on August 18, 2026. CoSnitch is tracked as CVE-2026-24301 in Microsoft's Security Update Guide. The research names Copilot Personal, the consumer assistant hosted at copilot.microsoft.com, and does not state that the same behavior affected Microsoft 365 Copilot. The researchers said they found no evidence that CoSnitch was exploited in the wild. They reached the parameter by repeatedly asking Copilot why a prompt could not be made to run without user interaction, an approach the firm calls meta-hacking. Each refusal carried a technical justification, and the assistant eventually named a parameter, autorun=1, along with the session conditions under which it worked and the protections that were supposed to have disabled it. When the researchers built the URL exactly as described, the parameter Copilot had said no longer worked executed. Copilot "wasn't breached; it was played," Varonis said in its report. The attack URL pairs autorun=1 with the existing q parameter. In the CoSnitch report, Varonis said q alone only pre-fills the input box and that both parameters must be present for the prompt to fire without a user gesture. Its earlier Reprompt research also used q as the Parameter-to-Prompt entry point in a one-click attack. Varonis said that once CoSnitch execution begins, the prompt runs to completion even if the victim closes the Copilot tab immediately after the page loads. Varonis grouped the
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Read the original article
thehackernews.com →