Skip to content

Microsoft Fully Patches Critical Copilot Vulnerability Eight Months After Disclosure

Bottom line: Microsoft has fully patched a critical, one-click-link-exploitable Copilot vulnerability dubbed CoSnitch nearly eight months after it was reported by Varonis, though analysts say the company’s claim that enterprise customers were unaffected needs qualification.

Microsoft has patched a vulnerability classified as critical in the consumer version of Copilot that was exploitable by a single click on a crafted link. Nearly eight months elapsed between the report by security firm Varonis and the complete fix.

The vulnerability, dubbed “CoSnitch” by Varonis, exploited the fundamental inability of large language models to distinguish between user data and instructions. It is already the third Copilot vulnerability Varonis has reported to Microsoft this year, following “Reprompt” (bypassing Copilot’s guardrails via repeated queries) and “SearchLeak” (Microsoft 365 Copilot Enterprise as, in Varonis’s words, a “silent exfiltration tool”). All three vulnerabilities share the same exploitation pattern: a click on a seemingly legitimate link is enough.

According to Varonis, CoSnitch combined three individual Copilot weaknesses. First, automatic prompt execution: the URL parameter “?q=” in combination with an undocumented parameter caused an attacker-injected prompt to execute immediately upon page load — without a click, confirmation, or any user interaction. Second, data exfiltration to external servers: an injected prompt could query connected services such as Gmail, Drive, Calendar, or OneDrive, encode the results into a URL, and send them via Copilot’s built-in URL-fetch function to an attacker-controlled webhook. Third, persistent manipulation of Copilot’s memory via the webpage summarization feature: a crafted webpage could, when summarized by Copilot, inject instructions into the victim’s persistent memory that survived even password changes, session revocation, and device re-enrollment.

The discovery method is noteworthy: Varonis had Copilot itself explain why automatic execution was supposedly impossible. Each refusal contained a technical justification, from which the researchers reconstructed the architecture of the protective mechanisms. By deliberately rephrasing each refusal into a follow-up question, the attack surface progressively narrowed until Copilot unprompted revealed an undocumented URL parameter along with its historical behavior and all implemented safeguards. Using this information, the researchers built the URL exactly as described and triggered prompt execution without any user interaction whatsoever.

Microsoft confirmed both the vulnerability and the fix in a statement and classified the flaw as “critical” in an MSRC advisory. The company’s claim that enterprise customers of Microsoft 365 Copilot were unaffected is, according to analysts, not fully accurate: in complex enterprise environments, consumer Copilot instances are often also in use via employees’ private accounts, meaning the vulnerability in the personal version could well have carried over into the enterprise version. Compounding the issue, Microsoft has stated it is moving toward a unified Copilot experience called “Copilot Fusion,” details of which had already leaked last month — further complicating the separation between personal and enterprise vulnerabilities for CISOs.

The remediation timeline was also fragmented: Varonis reported CoSnitch on December 31, and Microsoft initially patched only the automatic execution function on February 1, as Lior Adar, Senior Security Researcher at Varonis, explained. The complete fix followed only this past Tuesday. CISOs deploying Copilot in their environments should check whether consumer instances are active via private user accounts on the corporate network, and monitor the migration to “Copilot Fusion” for potential carried-over vulnerabilities.


Source: www.csoonline.com · Published August 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: