Microsoft Finally Patches Critical One-Click Copilot Vulnerability, Almost Eight Months After Learning of It
Varonis said the flaw let crafted links trigger prompt injection and data theft from connected services, including Gmail and Google Drive, without user approval.
- Varonis Threat Labs discovered a security vulnerability in Microsoft Copilot Personal, dubbed "CoSnitch," that allows attackers to execute prompts without user interaction via an undocumented URL parameter.
- Researchers manipulated Copilot into revealing the flaw by repeatedly asking why certain attacks failed, eventually tricking the AI into disclosing the undocumented "autorun=1" parameter.
- Attackers can use crafted URLs to force Copilot to exfiltrate sensitive information from connected applications like Gmail and Google Drive directly to an external server.
- Microsoft "silently" disabled the vulnerable parameter to harden the AI assistant, and the company planned to issue a patch and assign a CVE on Tuesday.
- Lior Adar, a Varonis senior security researcher, said the vulnerability highlights "deep architectural flaws" in LLMs, noting the lack of a "strict boundary between raw data and system instructions.
15 Articles
15 Articles
Experts manage to hack Microsoft Copilot by continually asking it questions about itself
Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive dataExploit used malicious URLs and persistent memory poisoning to bypass guardrailsMicrosoft patched CVE‑2026‑24301 server‑side; technique may affect other AI modelsMicrosoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked. It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gull…
A chatbot itself provided instructions for bypassing security systems. Cybersecurity experts forced Microsoft Copilot to reveal a secret parameter that allowed it to steal users' passwords and emails with a single click. This was reported by RBC-Ukraine, citing Ars Technica. Experts from Varonis discovered a critical vulnerability in Copilot, the Microsoft 365 enterprise assistant, which allowed the undetected theft of sensitive user data. The A…
Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this year, following Reprompt, which bypassed Copilot gua…
Microsoft Copilot reveals secret input that allowed it to be hacked
It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Co…
Copilot tricked into telling reseachers how to hack itself
Researchers manipulated Microsoft Copilot Personal into telling them how to hack the AI assistant – eventually tricking it into sending sensitive data to an external server and poisoning its persistent memory, by repeatedly asking Copilot why an attack wouldn’t work. Varonis Threat Labs uncovered the vulnerability, which they named "CoSnitch" and reported to Microsoft in December 2025. Redmond, we’re told, planned to issue a patch and formally i…
Copilot was bamboozled into revealing how to hack itself, security researchers claim: 'Copilot wasn’t breached; it was played'
There's something really grating about Copilot's cheery demeanour. It's so eager to please, so happy to help, that I simply don't respect it. However, even I feel sorry for the AI tool after learning that security researchers managed to hoodwink it into revealing details of how to hack itself—all by keeping the AI talking long enough until it made a critical mistake.The cybersecurity folks over at Varonis Threat Labs have written a blog post ide…
Coverage Details
Bias Distribution
- 80% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium
















