Research Microsoft Copilot Personal ai-ml Microsoft data-breach
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
CVE Tools coverage
Varonis Threat Labs identified three vulnerabilities, dubbed CoSnitch, in Microsoft Copilot Personal that permit attackers to silently extract data from connected services through a single malicious link click. The flaws, tracked as CVE-2026-24301, exploit an undocumented URL parameter to execute prompts within the victim's authenticated session without user interaction. Although no evidence of real-world exploitation was found, the issue allowed access to emails, calendar entries, and file metadata linked to the user's account. Microsoft deployed patches on August 18, 2026, addressing these issues which included the ability to persistently inject instructions into the assistant's memory store.