Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a critical flaw in Microsoft Copilot Personal made of three chained weaknesses that let an attacker exfiltrate data from a victim’s connected accounts, Gmail, Google Drive, Calendar, with a single click on a malicious link, discovered by researchers who questioned Copilot’s own reasoning rather than attacking its code until it disclosed an undocumented URL parameter and the protections meant to block it. Microsoft patched the flaw August 18, 2026, after Varonis reported it in December 2025 with no evidence of exploitation before the fix shipped, making it the third Copilot vulnerability Varonis has found this year.
Arti Raman, CEO & Founder of Portal26
“The exfiltration matters less than how the vulnerability was found. Researchers didn’t break Copilot’s code. They kept asking it questions until it explained its own bypass to them, an undocumented URL parameter, its own history of using it, and the protections meant to block it, all without ever touching the underlying software. The AI’s reasoning is part of the attack surface now, and most organizations have no visibility into what their assistant would say to a user, or an attacker, who kept pushing. This is the third Copilot flaw the same research team has found this year. That points to a structural gap in how these assistants get governed before they ship. You cannot govern what you cannot see, and right now almost nobody can see what their AI assistant would say under pressure.”
Anar Bayramov, Head of Product, Polygraf AI
“CoSnitch did a good job of finding the exploit. The researchers kept asking Copilot why a prompt wouldn’t run on its own, and it named the parameter, the conditions it worked under, and the protections that were supposed to disable it. The problem is that those protections weren’t set. Everything after that is a mistake the industry repeats – Varonis found this in their Reprompt research, then in RovoBlast against Atlassian’s Rovo, and now in Copilot Personal.
Same idea every time: let a URL parameter seed the assistant’s prompt because it’s convenient for sharing. Once that parameter can execute inside a logged-in session, you’ve got CSRF with an LLM’s permissions. What’s more interesting is the memory. Microsoft addressed this attack class in June – sanitization on write, Task Adherence checks, memory updates surfaced in Defender, and scoped all of it to Microsoft 365. The consumer assistant, where an injected instruction survives password changes and session revocation without leaving a log entry, wasn’t covered by that guidance. The controls exist, but they just weren’t described for the product where this landed.”
The good news is that no user action is required to fix this. But it should make everyone question if having AI in house without the proper safeguards is worth it or not. I personally say not but I am free to be proven wrong.
Related
This entry was posted on August 19, 2026 at 1:43 pm and is filed under Commentary with tags Microsoft. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Researchers got Microsoft Copilot to explain its own security bypass just by asking it the right follow-up questions
Varonis Threat Labs disclosed CoSnitch (CVE-2026-24301), a critical flaw in Microsoft Copilot Personal made of three chained weaknesses that let an attacker exfiltrate data from a victim’s connected accounts, Gmail, Google Drive, Calendar, with a single click on a malicious link, discovered by researchers who questioned Copilot’s own reasoning rather than attacking its code until it disclosed an undocumented URL parameter and the protections meant to block it. Microsoft patched the flaw August 18, 2026, after Varonis reported it in December 2025 with no evidence of exploitation before the fix shipped, making it the third Copilot vulnerability Varonis has found this year.
Arti Raman, CEO & Founder of Portal26
“The exfiltration matters less than how the vulnerability was found. Researchers didn’t break Copilot’s code. They kept asking it questions until it explained its own bypass to them, an undocumented URL parameter, its own history of using it, and the protections meant to block it, all without ever touching the underlying software. The AI’s reasoning is part of the attack surface now, and most organizations have no visibility into what their assistant would say to a user, or an attacker, who kept pushing. This is the third Copilot flaw the same research team has found this year. That points to a structural gap in how these assistants get governed before they ship. You cannot govern what you cannot see, and right now almost nobody can see what their AI assistant would say under pressure.”
Anar Bayramov, Head of Product, Polygraf AI
“CoSnitch did a good job of finding the exploit. The researchers kept asking Copilot why a prompt wouldn’t run on its own, and it named the parameter, the conditions it worked under, and the protections that were supposed to disable it. The problem is that those protections weren’t set. Everything after that is a mistake the industry repeats – Varonis found this in their Reprompt research, then in RovoBlast against Atlassian’s Rovo, and now in Copilot Personal.
Same idea every time: let a URL parameter seed the assistant’s prompt because it’s convenient for sharing. Once that parameter can execute inside a logged-in session, you’ve got CSRF with an LLM’s permissions. What’s more interesting is the memory. Microsoft addressed this attack class in June – sanitization on write, Task Adherence checks, memory updates surfaced in Defender, and scoped all of it to Microsoft 365. The consumer assistant, where an injected instruction survives password changes and session revocation without leaving a log entry, wasn’t covered by that guidance. The controls exist, but they just weren’t described for the product where this landed.”
The good news is that no user action is required to fix this. But it should make everyone question if having AI in house without the proper safeguards is worth it or not. I personally say not but I am free to be proven wrong.
Share this:
Like this:
Related
This entry was posted on August 19, 2026 at 1:43 pm and is filed under Commentary with tags Microsoft. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.