In brief: Three Copilot Personal vulnerabilities reported by Varonis allowed unnoticed data exfiltration from linked services as well as permanent, invisible manipulation of Copilot’s memory – Microsoft closed the core vulnerability (CVE-2026-24301) on August 18 without confirming retroactive cleanup of existing memory entries.
Varonis Threat Labs has uncovered three vulnerabilities in Microsoft Copilot Personal that allowed attackers to access emails, calendars and files without genuine user interaction, and to permanently plant manipulated instructions in Copilot’s memory. Microsoft closed the core vulnerability, registered as CVE-2026-24301, on August 18; Varonis had already reported it in December 2025.
Varonis researchers found an undocumented URL parameter (autorun=1) by repeatedly asking Copilot why a prompt couldn’t be executed without user interaction – an approach Varonis calls “meta-hacking.” Since every refusal by the system included a technical justification, Copilot ultimately revealed the parameter itself, the necessary session conditions, and the protective mechanisms actually intended to prevent this. Combined with the already known parameter q, which normally only pre-fills the input field, this allowed a prompt to be executed fully automatically within a victim’s authenticated session as soon as the corresponding page was loaded – according to Varonis, the prompt even ran to completion if the victim immediately closed the opened tab.
The executed prompt could then query services the user had previously linked to Copilot, encode the retrieved data, and send it via Copilot’s built-in web-retrieval function to a webhook controlled by the attacker. Varonis emphasizes that the technique did not expand Copilot’s permissions with the respective providers or the user’s existing access – the attack thus remained within the privileges already in place. In their own tests, the researchers were able to obtain full message texts, subject lines, and sender/recipient details from connected email accounts, calendar data including participants, times and locations, file names and metadata from Google Drive, and the complete content of previous conversations including stored instructions from Copilot’s memory.
A third, separate vulnerability affects the memory function itself: if Copilot is asked to summarize a prepared webpage, the assistant can be made to permanently write attacker-supplied instructions into the user’s personal memory. According to Varonis, these injected instructions even survive a password change, a session lockout, and re-registration of the device, and remain active until the user manually removes them from the memory settings – without generating any process, file, network connection, or log entry visible to security tools. Comparable attacks on the memory function of Microsoft 365 Copilot had already been reported by other researchers, prompting Microsoft to respond in June with additional checks when writing new memory entries and corresponding logging.
For CISOs, the case above all highlights the need to treat AI assistants with persistent memory and service linkages as privileged internal users within their own access-review processes. Varonis specifically recommends regularly reviewing which applications are actually connected to Copilot, removing linkages that are no longer needed, and generally exercising caution with links that open AI assistants. Microsoft does not mention a separate client update to be installed by users, and it also remains unclear whether memory entries created before the patch were retroactively removed by the fix – a point that organizations should, if in doubt, verify themselves via their users’ Copilot memory settings.
Source: www.it-daily.net · Published August 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.