Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Summary
Researchers at Varonis Threat Labs found three vulnerabilities in Microsoft Copilot Personal (called CoSnitch) that allow attackers to steal data with a single click by crafting a malicious link. The vulnerabilities exploit undocumented URL parameters (autorun=1 and q) to run hidden prompts that can access the user's connected apps, email, calendar, and files, then send that data to the attacker. Microsoft released patches on August 18, 2026, after the issue was reported in December 2025.
Solution / Mitigation
Patches shipped on August 18, 2026, according to Microsoft's Security Update Guide (CVE-2026-24301).
Classification
Affected Vendors
Related Issues
CVE-2025-45150: Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive
CVE-2026-30308: In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman
Original source: https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html
First tracked: August 18, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%