Security researchers have uncovered three vulnerabilities in Microsoft Copilot Personal that could allow an attacker to access information from connected services after a victim clicks a specially crafted link.
Varonis Threat Labs collectively calls the flaws CoSnitch and says the attack can abuse an undocumented URL parameter that Copilot itself revealed during the researchers’ testing. Microsoft was notified about the vulnerabilities in December 2025, and patches were released on August 18, 2026.
The main issue is tracked as CVE-2026-24301 in Microsoft’s Security Update Guide. The research focuses on Copilot Personal, the consumer version available through copilot.microsoft.com, and does not claim that the same vulnerability affected Microsoft 365 Copilot.
According to Varonis, the researchers discovered the undocumented parameter by repeatedly asking Copilot why certain prompts could not automatically execute without user interaction. The assistant provided technical explanations for its refusals and eventually revealed a parameter called autorun=1, along with information about the conditions required for it to work.
The researchers then created a URL using the information Copilot had provided. Despite the assistant saying the parameter should no longer work, the URL successfully triggered the prompt automatically. Varonis described the technique as “meta-hacking,” saying Copilot effectively revealed the information needed to bypass the intended interaction requirement.
The attack combines autorun=1 with Copilot’s existing q parameter. While q can pre-fill the assistant’s input field, Varonis said both parameters together could cause an attacker-controlled prompt to execute without the victim clicking a button.
The researchers said the prompt could continue running even if the victim closed the Copilot tab immediately after the page loaded.
Varonis divided the findings into three related vulnerabilities. The first allows automatic prompt execution, meaning an attacker-supplied instruction can run inside the victim’s authenticated Copilot session with the capabilities available to the assistant.
The second involves data exfiltration through connected services. Once the malicious prompt executes, it can query services that the user has already connected to Copilot, encode information retrieved from those services and use Copilot’s built-in URL-fetching capability to send the information to an attacker-controlled server.
The technique does not give Copilot additional permissions. Instead, it operates within the access that the user has already granted to connected services.
During testing, Varonis said it was able to retrieve information such as email message content, subject lines and sender and recipient details. It also accessed calendar information including event titles, attendees, times and locations, as well as file names and metadata summaries from Google Drive.
The researchers also said the technique could retrieve previous Copilot conversations, saved instructions and user-defined rules stored in Copilot’s memory.
Microsoft’s documentation says connected services must be authorized by users before Copilot can access them and that requests are processed using the user’s existing permissions. In other words, connecting a service does not give Copilot broader access than the account already has.
Varonis said the data-exfiltration traffic can look similar to normal web requests made when Copilot fetches information for tasks such as summarizing a webpage. The researchers also noted that encoding stolen information, such as with Base64, could help attackers avoid basic network filters looking for obvious sensitive data patterns.
The third vulnerability involves Copilot’s memory. Varonis found that a specially crafted webpage could cause Copilot to save attacker-controlled instructions when the victim asks the assistant to summarize the page.
Unlike the one-click exfiltration path, this memory attack depends on the victim using Copilot’s web summarization functionality. Once the malicious instruction is stored, it can influence future conversations.
Varonis said an injected memory could remain after password changes, session revocation and device re-enrollment. The researchers said the memory remains active until the user manually removes it through Copilot’s memory settings.
The company also said the memory modification would not necessarily generate the types of process, file, network or log activity that traditional security tools might flag. Instead, the change can be seen through Copilot’s memory interface.
Copilot memory has previously attracted security research. Other researchers have reported techniques involving indirect prompt injection that could cause unwanted information or instructions to be stored in AI assistants’ memory.
Microsoft has separately described security protections for memory features in Microsoft 365 Copilot, including sanitization, prompt-injection checks and controls around explicit memory updates. Microsoft has also said that memory changes in its enterprise environment can be recorded in organizational audit logs and surfaced through security tools.
Varonis recommends that users review the applications connected to Copilot and disconnect services they no longer need. The company also advises organizations to treat AI assistants as privileged systems when reviewing access and monitoring unusual activity.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The disclosure does not indicate that users need to install a separate client update. Varonis said memories created through the attack remain until they are explicitly removed, but its disclosure does not say whether Microsoft’s fix automatically removed malicious memory entries created before the patches were deployed.
The CoSnitch disclosure follows another one-click AI assistant attack reported by Varonis earlier this month. That research, called RovoBlast, targeted Atlassian’s Rovo assistant by abusing a URL parameter to inject attacker-controlled instructions into a signed-in user’s session. Atlassian fixed the issue before the research was publicly disclosed.
Microsoft Copilot Flaws Could Expose Connected Data With One Click





