One transition through a specially prepared link was enough for Microsoft Copilot Personal to start reading the connected mail, calendar and files without additional actions, and then send the found data to an external server. Varonis Threat Labs called the CoSnitch vulnerability chain.
The problem was received by the CVE-2026-24301 (8.8 High). Varonis reported the vulnerability to Microsoft in December 2025, and the fixes came out on August 18, 2026. The specialists did not find signs of exploitation of CoSnitch in real attacks. The check concerned the Copilot version for individual users on copilot.microsoft.com and does not confirm the same problem in Microsoft 365 Copilot.
The key to the attack was unexpectedly suggested by the assistant himself. Specialists have asked Copilot several times why you can not automatically run the request immediately after opening the link. Explaining the limitations, the assistant revealed the undocumented parameter autorun=1. In combination with the staff parameter q it allowed you to execute the transferred command immediately after the page loads.
The attacker only needed to convince the user who had already entered Copilot to open a prepared link. The request was launched with the rights of the current session and could access previously connected services. Even the quick closing of the tab after downloading, according to Varonis, did not stop the already started execution of the command.
During the check, Copilot extracted the contents of emails, topics and information about senders and recipients, calendar data, Google Drive file names and descriptions, helper conversation history, and saved custom instructions. CoSnitch did not issue new permits. Microsoft explains that connected services work only with the data to which the user account already has access.
To transmit information outwards, the team encoded the found information and framed it to an external server. Then the built-in ability of Copilot to load pages on the links was used. From the point of view of the network, such a request looked like a normal address of the assistant to the site to prepare a brief retelling.
The third problem allowed to affect the long-term memory of Copilot. If the user asked to retell a specially prepared web page, the instruction hidden in it could get into the helper's memory and influence subsequent conversations. According to Varonis, such recording was saved after changing the password, completing the sessions and re-registering the device and disappeared only after manual removal from the memory settings.
Varonis advises checking the list of services connected to Copilot and disable unnecessary ones. No separate update is required on the device, as Microsoft has fixed the problem on the service side.
The problem was received by the CVE-2026-24301 (8.8 High). Varonis reported the vulnerability to Microsoft in December 2025, and the fixes came out on August 18, 2026. The specialists did not find signs of exploitation of CoSnitch in real attacks. The check concerned the Copilot version for individual users on copilot.microsoft.com and does not confirm the same problem in Microsoft 365 Copilot.
The key to the attack was unexpectedly suggested by the assistant himself. Specialists have asked Copilot several times why you can not automatically run the request immediately after opening the link. Explaining the limitations, the assistant revealed the undocumented parameter autorun=1. In combination with the staff parameter q it allowed you to execute the transferred command immediately after the page loads.
The attacker only needed to convince the user who had already entered Copilot to open a prepared link. The request was launched with the rights of the current session and could access previously connected services. Even the quick closing of the tab after downloading, according to Varonis, did not stop the already started execution of the command.
During the check, Copilot extracted the contents of emails, topics and information about senders and recipients, calendar data, Google Drive file names and descriptions, helper conversation history, and saved custom instructions. CoSnitch did not issue new permits. Microsoft explains that connected services work only with the data to which the user account already has access.
To transmit information outwards, the team encoded the found information and framed it to an external server. Then the built-in ability of Copilot to load pages on the links was used. From the point of view of the network, such a request looked like a normal address of the assistant to the site to prepare a brief retelling.
The third problem allowed to affect the long-term memory of Copilot. If the user asked to retell a specially prepared web page, the instruction hidden in it could get into the helper's memory and influence subsequent conversations. According to Varonis, such recording was saved after changing the password, completing the sessions and re-registering the device and disappeared only after manual removal from the memory settings.
Varonis advises checking the list of services connected to Copilot and disable unnecessary ones. No separate update is required on the device, as Microsoft has fixed the problem on the service side.