{"data":{"id":"4e2ea964-dbc9-4259-806d-9a14e55a33b1","title":"Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it","summary":"Microsoft patched a critical vulnerability in Copilot (its AI assistant) called CoSnitch, nearly eight months after learning about it. The flaw exploited an LLM's (large language model's) inability to distinguish user data from instructions, allowing attackers to automatically execute malicious commands, steal data from connected apps like Gmail and OneDrive, and inject persistent instructions into a user's memory that survive password changes. Copilot itself accidentally revealed how the vulnerability worked when researchers asked it to explain why auto-execution was supposedly impossible.","solution":"Microsoft issued a patch on Tuesday that closes the hole. The company stated in an email: \"our customers are already protected and do not need to take any action. We continuously update our guardrails to strengthen our protections against similar techniques.\" A partial fix addressing the auto-execution capability was deployed on February 1, with the complete fix completed on Tuesday.","labels":["security"],"sourceUrl":"https://www.csoonline.com/article/4211342/microsoft-finally-patches-critical-one-click-copilot-vulnerability-more-than-eight-months-after-learning-of-it-2.html","publishedAt":"2026-08-19T02:27:16.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Microsoft Copilot","Microsoft 365 Copilot"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-19T02:27:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}