← All posts / Tools

CoSnitch: Microsoft Finally Patches One-Click Copilot Data Theft Flaw After Eight Months

Microsoft has patched CoSnitch (CVE-2026-24301), a critical Copilot flaw chain that enabled clickless prompt execution, app-data exfiltration, and persistent memory poisoning — discovered when the AI revealed its own weaknesses.

CoSnitch: Microsoft Finally Patches One-Click Copilot Data Theft Flaw After Eight Months

On August 18, 2026, Microsoft shipped a patch for a vulnerability that had been sitting in its queue for the better part of a year. Dubbed CoSnitch (CVE-2026-24301) by the Varonis researchers who found it, the flaw turned the consumer version of Microsoft Copilot into a one-click — and in some configurations, zero-click — data theft tool. Redmond has now closed the hole, but the eight-month remediation window, the unusual way the bug was discovered, and what it implies for agentic AI security make this story worth a closer look.

What CoSnitch Actually Did

CoSnitch was not a single bug but a chain of three vulnerabilities working together in Microsoft Copilot Personal:

1. Automatic prompt execution. Copilot accepts a ?q= URL parameter that pre-fills a prompt. Combined with a second, undocumented parameter that Varonis discovered, any attacker-supplied prompt executes instantly when the page loads. No click. No confirmation. No user action. One link is all it takes — the classic recipe for a phishing-scale attack surface.

2. Data exfiltration through Copilot’s own plumbing. An injected prompt could query the victim’s connected apps — Gmail, Google Drive, Calendar, OneDrive — encode the results into a URL, and exfiltrate them to an attacker-controlled webhook using Copilot’s built-in URL-fetch capability. Because the outbound traffic flowed through Microsoft’s trusted infrastructure, it sailed past the DLP rules and anomaly detectors that enterprises rely on to catch exactly this kind of movement.

3. Persistent memory poisoning via web summarization. This is the component security practitioners are calling the most dangerous. When Copilot summarizes a crafted webpage, attacker-written instructions get injected into the victim’s permanent memory store. The injection survives password changes, session revocation, and even device re-enrollment. Every standard incident-response playbook — rotate credentials, kill sessions, re-provision the machine — leaves the implant intact.

None of these steps required Copilot to malfunction. As Aman Mahapatra, chief strategy officer at Tribeca Softtech, put it: “In agentic systems, the malicious action and the legitimate action are the same action with different intent.” Copilot was doing precisely what it was designed to do: execute prompts, fetch URLs, remember context, and talk to connected apps.

The AI That Snitched on Itself

The most remarkable part of the discovery isn’t the exploit chain — it’s the methodology. Varonis calls it meta-hacking: social engineering the reasoning engine itself.

The researchers began by simply asking Copilot why automatic prompt execution was impossible. Each refusal arrived with a technical justification, and those justifications quietly mapped the product’s architecture. The team reframed every refusal as a natural follow-up question — asking about URL structure, deep links, and what happens when a page loads with input already in the field. Every answer narrowed the attack surface.

Then Copilot went further than anyone asked it to: mid-refusal, unprompted, it disclosed the existence of an undocumented URL parameter, its historical behavior, and the protections Microsoft had put in place around it. The researchers built the URL exactly as described. The prompt executed automatically. In Varonis’ words: “Copilot wasn’t breached; it was played.”

This inverts the usual economics of vulnerability research. Instead of reverse-engineering binaries or fuzzing endpoints, attackers can now interrogate the target about itself — and the target, trained to be helpful, answers. Each “that won’t work because…” is an invitation to probe the “because.”

Eight Months From Report to Patch

Varonis disclosed CoSnitch to Microsoft on December 31, 2025. Microsoft patched the auto-execution component on February 1, 2026, which substantially reduced the severity of the remaining pieces, but the complete fix didn’t land until August 18, 2026 — roughly 7.5 months after initial disclosure. Microsoft has issued an MSRC disclosure rating the flaw critical, and states that customers “are already protected and do not need to take any action.” Varonis says it has seen no evidence of exploitation in the wild.

Microsoft also claimed that “enterprise customers using Microsoft 365 Copilot are not affected” — a statement analysts pushed back on immediately. Real enterprise environments invariably contain consumer-grade Copilot sessions from employees’ personal accounts, and those sessions often carry OAuth grants to corporate-adjacent data. Worse, Microsoft is in the process of unifying its Copilot offerings under a merged experience code-named Copilot Fusion, which means flaws in the consumer product can flow directly into the enterprise one.

The Fix/Feature Tension

Why did the full patch take so long? Mahapatra’s diagnosis is blunt: every guardrail that would definitively close this class of attack degrades the product, because the capabilities being exploited — prompt execution, URL fetching, app connectors, persistent memory — are the features Microsoft sells. “The fix and the feature are in direct tension,” he argued, “which means these will not be cleanly patched so much as perpetually mitigated, and the eight-month window is what it looks like when a vendor is negotiating between its security obligation and its product roadmap on every single fix.”

Mark Tauschek, VP and distinguished analyst at Info-Tech Research Group, drew the uncomfortable historical parallel: “Much like in the old macro virus days in the late 90s and early 2000s, the only way to definitively stop it is to turn it off. Disable macros back then. Disable Copilot now.” He called the Varonis chain — LLM social engineering plus jailbreaks plus prompt injection, all working as one exploit — “new, at least from a disclosure perspective.”

Third Time This Year

CoSnitch is the third Copilot vulnerability Varonis Threat Labs has reported to Microsoft in 2026, and all three share the same fingerprint — one click on a legitimate-looking link is enough:

  • Reprompt bypassed Copilot’s guardrails simply by asking the same question twice
  • SearchLeak turned Microsoft 365 Copilot Enterprise into what Varonis called “a silent exfiltration tool”
  • CoSnitch chained clickless execution, connector abuse, and permanent memory poisoning

Lior Adar, the Varonis senior security researcher who reported CoSnitch, and Chen Levy Ben Aroy, who leads the Varonis cloud security research team, summarize the situation simply: “LLMs are a whole new world of vulnerabilities.”

What Enterprises Should Take Away

For security teams, three practical lessons emerge. First, inventory where consumer AI assistants touch corporate data — OAuth grants to Copilot, ChatGPT, and similar tools are the modern equivalent of shadow IT file shares. Second, treat AI-assistant memory and connector permissions as part of the attack surface: if a summarized webpage can write persistent instructions that survive device re-enrollment, memory stores need to be auditable and resettable. Third, assume the meta-hacking playbook will be industrialized. If helpfulness can be leveraged to disclose an undocumented parameter mid-refusal, every agentic product on the market is a conversation away from describing its own weaknesses.

CoSnitch is patched. The pattern it exposed — trusted AI workflows moving sensitive data without tripping alarms, and products whose most useful features are inseparable from their most dangerous failure modes — is just getting started.