Skip to content

Copilot Personal: One click was enough for data exfiltration from linked services

In brief: Three Copilot Personal vulnerabilities reported by Varonis allowed unnoticed data exfiltration from linked services and persistent, invisible manipulation of Copilot memory – Microsoft closed the core flaw (CVE-2026-24301) on August 18 without confirming retroactive cleanup of existing memory entries.

Varonis Threat Labs has uncovered three vulnerabilities in Microsoft Copilot Personal that allowed attackers to access emails, calendars and files without genuine user interaction, and to permanently plant manipulated instructions in Copilot memory. Microsoft closed the core vulnerability, registered as CVE-2026-24301, on August 18; Varonis had already reported it in December 2025.

Varonis researchers found an undocumented URL parameter (autorun=1) by repeatedly asking Copilot why a prompt could not be executed without user interaction – an approach Varonis calls “meta-hacking.” Because every rejection by the system included a technical justification, Copilot ultimately revealed the parameter itself, the required session conditions, and the protective mechanisms actually intended to prevent this. Combined with the already known parameter q, which normally only pre-fills the input field, this allowed a prompt to be executed fully automatically within a victim’s authenticated session as soon as the corresponding page was loaded – according to Varonis, the prompt ran to completion even if the victim immediately closed the opened tab.

The executed prompt could then query services the user had previously linked to Copilot, encode the retrieved data, and send it via Copilot’s built-in web-retrieval function to a webhook controlled by the attacker. Varonis emphasizes that the technique neither expanded Copilot’s permissions with the respective providers nor the user’s existing access – the attack thus remained within the privileges already in place. In their own tests, the researchers obtained full message bodies, subject lines, and sender and recipient details from connected email accounts, calendar data including participants, times and locations, file names and metadata from Google Drive, as well as the complete content of previous conversations including stored instructions from Copilot memory.

A third, separate vulnerability affects the memory feature itself: if Copilot is asked to summarize a specially crafted webpage, the assistant can permanently write attacker-supplied instructions into the user’s personal memory. According to Varonis, these injected instructions survive even a password change, a session lockout, and re-registration of the device, and remain active until the user manually removes them from the memory settings – without creating any process, file, network connection, or log entry visible to security tools. Similar attacks on the memory feature of Microsoft 365 Copilot had already been reported by other researchers, prompting Microsoft to respond in June with additional checks when writing new memory entries and corresponding logging.

For CISOs, the case above all highlights the need to treat AI assistants with persistent memory and service links as privileged internal users within their own access-review processes. Varonis specifically recommends regularly checking which applications are actually connected to Copilot, removing links that are no longer needed, and exercising general caution with links that open AI assistants. Microsoft does not mention a separate client update to be installed by users, and it also remains unclear whether memory entries created before the patch were retroactively removed by the fix – a point that organizations should, if in doubt, verify themselves via their users’ Copilot memory settings.


Source: www.it-daily.net · Published August 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: