'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
Varonis Threat Labs disclosed a series of vulnerabilities in Microsoft Copilot Personal, collectively dubbed "CoSnitch," which enable threat actors to extract internal architectural details and exfiltrate sensitive data. The attack chain relies on a technique called "meta-hacking" to map the system's behavior, followed by the use of specially crafted URLs containing an undocumented ?autorun=1 parameter to trigger automatic prompt execution within a victim's authenticated session. This allows attackers to access connected services such as Gmail and Google Drive without further user interaction. Microsoft assigned the flaw as CVE-2026-24301, rating it 8.8 on CVSS 3.1, and deployed a patch on August 18, 2025. While enterprise customers are reportedly unaffected and no in-the-wild exploitation has been observed, researchers warn that personal instances linked to corporate accounts pose a significant risk.