Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Summary
Microsoft patched a critical vulnerability in Copilot (its AI assistant) called CoSnitch, nearly eight months after learning about it. The flaw exploited an LLM's (large language model's) inability to distinguish user data from instructions, allowing attackers to automatically execute malicious commands, steal data from connected apps like Gmail and OneDrive, and inject persistent instructions into a user's memory that survive password changes. Copilot itself accidentally revealed how the vulnerability worked when researchers asked it to explain why auto-execution was supposedly impossible.
Solution / Mitigation
Microsoft issued a patch on Tuesday that closes the hole. The company stated in an email: "our customers are already protected and do not need to take any action. We continuously update our guardrails to strengthen our protections against similar techniques." A partial fix addressing the auto-execution capability was deployed on February 1, with the complete fix completed on Tuesday.
Classification
Affected Vendors
Related Issues
CVE-2025-45150: Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive
CVE-2026-30308: In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman
First tracked: August 19, 2026 at 02:00 AM
Classified by LLM (prompt v3) · confidence: 92%