What happened
Security firm Varonis published details of CoSnitch, a chain of three vulnerabilities in Microsoft Copilot Personal that could have let an attacker siphon data from a victim's connected accounts with a single click on a crafted link. The link abused a parameter that auto-ran a hidden prompt the moment Copilot loaded. That prompt could then query services the victim had connected through OAuth — such as Gmail, Google Drive, and Calendar — encode the results, and send them to an attacker's server using Copilot's built-in ability to fetch URLs. A third technique planted attacker instructions in Copilot's persistent memory, where they survived password changes. Varonis reported the issue in December 2025; Microsoft disabled the auto-run behavior in February and completed the fix on August 18, assigning CVE-2026-24301 with an 8.8 severity rating. Neither company found evidence the flaw was exploited in the wild. Varonis also noted that Copilot's own explanations of its safeguards helped researchers map the attack — an approach the firm calls meta-hacking.
Why it matters for your business
AI assistants are quickly becoming the most-connected apps your employees have: one login, wired through connectors to email, files, and calendars. That is exactly why one malicious link was enough here — the assistant already held the keys. This is the third Copilot flaw Varonis has disclosed this year, following Reprompt and SearchLeak, and the underlying pattern applies to any AI tool your staff connects to business data, not just Microsoft's. The permissions you grant an assistant are permissions you grant to whoever can trick it.
What to do about it
- Inventory which AI assistants your team uses and which accounts are connected to them.
- Grant connectors only the access they need, and disconnect the ones nobody uses.
- Treat links that open an AI assistant with the same suspicion as an unexpected login page.
