Full research report

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Original reporting โ†—
โ˜… Threat intelligence assessment medium confidence

Executive assessment

Varonis uncovered a trio of vulnerabilities in Microsoft Copilot Personal, allowing attacker-crafted links to trigger unauthorised data access and exfiltration from connected services with a single click. Microsoft issued patches addressing the flaws on August 18, 2026, and researchers confirmed the risks without reporting active exploitation. The vulnerabilities involved both prompt auto-execution and persistent, undetected memory poisoning via Copilotโ€™s web summarisation feature. Defensive postures should prioritise update deployment, audit of past Copilot memory and activity, and close monitoring for anomalous behaviours or unauthorised third-party connections. There is no practical evidence of exploitation in the wild, but the attack surface and technical vector present significant risk if unpatched.

What happened

Varonis Threat Labs reported three vulnerabilities in Microsoft Copilot Personal, collectively known as CoSnitch, which enabled silent exfiltration of data from connected apps through crafted URLs. Microsoft patched the flaws on August 18, 2026.

Affected scope

Microsoft Copilot Personal (consumer version at copilot.microsoft.com); confirmed exposure for integrations like Google Drive, email, calendar; Microsoft 365 Copilot not confirmed affected.

Technical assessment

A crafted URL could trigger automatic prompt execution within the authenticated Copilot session. This allowed attacker-supplied prompts to exfiltrate data from services authorised by the user, using Copilot's URL fetch to transmit content to third-party webhooks. A separate vector allowed persistent memory manipulation via web summarisation.

Recommended defensive actions

  1. Apply the August 18, 2026 Copilot security update immediately.
  2. Audit connected Copilot services and memory store for unauthorised entries, instructions, or history.
  3. Monitor network logs for anomalous Copilot activity, especially unexpected external endpoint access.
  4. Review user permissions on connected third-party accounts and restrict unnecessary integrations.

Uncertainties and evidence gaps

  • No public evidence exists for in-the-wild exploitation as of disclosure.
  • Unclear if all variants (including Microsoft 365 Copilot) exhibit identical risk.
  • Undetectable memory store changes lack log/audit signals outside Copilot's interface.
  • The supplied reporting identifies CVE-2026-24299, but the reviewed sources did not establish its distinct role in this event.
  • The supplied reporting identifies CVE-2026-24301, but the reviewed sources did not establish its distinct role in this event.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessAttacker needs the user to open a crafted link while authenticated to Copilot.
ComponentCopilot Personal web front-end and memory store.
MechanismAbuse of undocumented URL parameters permitting auto-execution of attacker-supplied prompts inside an authenticated session.
ImpactData exfiltration from all services the victim has authorised to Copilot; persistent memory injection affecting future sessions.
DetectionChanges to Copilot memory visible in the web interface; exfiltrations indistinguishable from normal fetch traffic.
MitigationApply the Microsoft security update and review/delete unwanted Copilot memory entries.
Exploitation status

No evidence of active exploitation; public technical write-ups exist.

The investigation began with public reporting from The Hacker News citing a Varonis disclosure regarding critical Microsoft Copilot Personal vulnerabilities. Research steps included verifying Microsoft advisories for the related CVEs, locating the original Varonis research post, and confirming whether technical proof-of-concept code or active exploitation evidence had surfaced. The confluence of official advisories, primary researcher reporting, and reputable journalism underpins a medium-to-high confidence that the events and scope are as described, with exploitation currently unreported.

  1. What are the primary details of the reported Copilot Personal vulnerabilities?
    Reviewed The Hacker News article.
    thehackernews.com โ†—

    Confirmed the nature of the vulnerabilities, involved parties, and public disclosure date.

    why Established baseline details for further verification.

  2. Has Microsoft released advisories for CVE-2026-24301 and CVE-2026-24299?
    Accessed Microsoft Security Update Guide for both CVEs.

    Confirmed vendor acknowledgement and patches.

    why Validates official recognition and remediation.

  3. What are the technical and operational mechanics of the attack?
    Scanned for Varonis's own research publication on their blog.

    Located a dedicated post describing attack flow, triggers (autorun=1), and proof-of-concept test details.

    why Source-validated mechanics behind the vulnerability.

  4. Are public PoCs or exploit repositories available?
    Searched GitHub for 'CoSnitch copilot exploit'.
    github.com โ†—

    No public exploit code or functional repositories found.

    why Limits the immediate practical threat and informs defensive posture.

  5. Is there OSINT/social media evidence of exploitation or actor interest?
    Checked Twitter/X for recent posts about 'CoSnitch copilot'.

    No significant ongoing actor or dark-web chatter discovered.

    why Suggests a lack of criminal operationalisation at this stage.

TargetsMicrosoft Copilot Personal usersGoogle DriveMail accountsConnected services

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 60 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful โ€” or not
The Hacker Newsnews ok9 records Primary evidence1 matched items Published the source report used to frame and date the event.
AlienVault OTXdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
BleepingComputernews ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1670 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5324 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok685 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1009 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked โ€” no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok7785 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok2 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok16 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok15 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok15 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP Galaxyresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Rapid7news ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Sigma Rulesresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Sophos IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 6 opened outside the registered collection
Analysis & research1
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps thehackernews.com โ†—

Summary of the incident and public disclosure.