CoSnitch Exploit Exposes Data Through Copilot
A single click on a maliciously crafted link was sufficient to trigger a severe data breach through Microsoft Copilot Personal. Astonishingly, without any further user interaction, the assistant would begin scanning connected emails, calendars, and files, subsequently exfiltrating the discovered data to an external server. Cybersecurity specialists at Varonis Threat Labs identified and named this sophisticated exploit chain “CoSnitch.”
Unveiling the Vulnerability
This critical vulnerability received the official designation CVE-2026-24301, carrying a High severity rating of 8.8. Varonis responsibly disclosed the flaw to Microsoft in December 2025, and the tech giant officially deployed the necessary remediations on August 18, 2026. Fortunately, security experts found absolutely no evidence indicating that threat actors had exploited CoSnitch in active, real-world cyberattacks.
The comprehensive investigation focused exclusively on the individual user iteration of Copilot, accessible via copilot.microsoft.com. Consequently, the findings do not definitively confirm the existence of this precise vulnerability within the enterprise-focused Microsoft 365 Copilot environment.
The Unexpected Discovery
In a surprising twist, the AI assistant itself inadvertently revealed the crucial key to the attack. The inquisitive specialists repeatedly interrogated Copilot, demanding to know why a query could not execute automatically immediately upon opening a link. While attempting to explain its own internal limitations, the assistant inadvertently disclosed a completely undocumented parameter: autorun=1.
When combined with the standard q parameter, this hidden command forced the assistant to execute the transmitted instruction the instant the webpage finished loading.
Executing the Attack
To successfully execute the exploit, a malicious actor merely needed to persuade a user, who was already actively logged into Copilot, to click on the carefully prepared link. The malicious query subsequently launched utilizing the privileges of the active session, granting it unfettered access to all previously connected services. Alarmingly, according to Varonis, even if the victim rapidly closed the browser tab immediately after the page loaded, the command execution process would persist unabated.
Data Extraction Capabilities
During their rigorous testing, the researchers observed Copilot effectively extracting the core contents of emails, subject lines, and detailed information regarding senders and recipients. Furthermore, it harvested sensitive calendar data, Google Drive file names and descriptions, the complete history of conversations with the assistant, and carefully saved user instructions. It is crucial to note that CoSnitch did not grant any new permissions; it merely abused existing access.
Microsoft explicitly clarified that these connected services operate exclusively utilizing data to which the specific user account already possesses legitimate access.
Exfiltration and Long-Term Memory Manipulation
To successfully exfiltrate the harvested information, the malicious command encoded the discovered data and appended it directly to the URL of an external server controlled by the attacker. Subsequently, the exploit abused Copilot’s innate capability to fetch and analyze external web pages via URLs. From a network monitoring perspective, this exfiltration request appeared entirely benign, masquerading as a standard assistant operation preparing a simple webpage summary.
Corrupting Copilot’s Memory
A third, deeply concerning vulnerability allowed attackers to maliciously manipulate Copilot’s long-term memory. If a victim instructed the assistant to summarize a specifically weaponized webpage, hidden instructions embedded within the page could infiltrate the assistant’s memory, subtly influencing all subsequent interactions. According to Varonis’s analysis, this insidious record persisted even after the user changed their password, terminated active sessions, and completely re-registered the device. The corrupted memory only vanished upon manual deletion from the assistant’s specific memory settings.
Remediation and Recommendations
Varonis strongly advises all users to meticulously review the list of services currently connected to their Copilot account and immediately disconnect any unnecessary integrations. Because Microsoft successfully remediated the underlying flaw directly on the server side, users do not need to install any localized updates or patches on their personal devices.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.