Skip to content

Three Vulnerabilities in Microsoft Copilot Personal Enable Data Exfiltration via a Single Click

Bottom line: According to Varonis Threat Labs, a manipulated link can be enough in Microsoft Copilot Personal to silently siphon data from connected apps.

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch. A single click on a crafted link is said to be sufficient to covertly extract data from connected apps and other information accessible to the victim within the Copilot session in the background.

In its analysis, Varonis Threat Labs describes three vulnerabilities in Microsoft Copilot Personal, jointly referred to as CoSnitch. The starting point is an undocumented URL parameter that is exposed by the assistant itself. According to the researchers, this parameter can be used to trigger a chain that allows an attacker to extract data from the active Copilot session as well as from connected applications with a single click by the victim on a crafted link, without any further interaction being necessary.

For security leaders, it is relevant that the attack chain does not target classic weaknesses such as flawed authentication, but rather the way Copilot Personal itself operates — in particular its integration with connected services and the contextual data available there. Since Copilot can access both business and personal data sources in many organizations, such a vulnerability extends the attack surface beyond the individual user to all applications and information linked to the account.

The available report does not indicate whether and to what extent Microsoft has already addressed the three vulnerabilities through patches; CVE identifiers and a concrete timeline for disclosure to the vendor are also missing. CISOs should review the use of Copilot Personal in their environment, inventory connected apps and their permissions, and consider awareness measures regarding phishing links related to Copilot sessions until the patch status is clarified.


Source: thehackernews.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: