CoSnitch – Microsoft Copilot Personal One-Click Data Exfiltration Flaws
First seen Aug 19, 2026 · Updated Aug 19, 2026
Varonis Threat Labs disclosed three vulnerabilities, collectively named CoSnitch, in Microsoft Copilot Personal that could allow an attacker to exfiltrate data from a victim's connected apps and Copilot session with a single click on a crafted link. The flaws exploit an undocumented URL parameter surfaced by the assistant itself, enabling silent data leakage without further user interaction.
Technical Analysis
The CoSnitch vulnerabilities abuse an undocumented URL parameter within Microsoft Copilot Personal that the assistant exposes, allowing a maliciously crafted link to trigger unauthorized queries against the victim's active Copilot session. Because Copilot integrates with connected applications (e.g., email, files, calendar), a successful exploit can silently pull sensitive data accessible to the LLM's context without additional clicks or explicit consent. This class of flaw highlights broader risks in agentic and RAG-style architectures where a conversational assistant is granted persistent access to multiple connected data sources under an implicit trust boundary. No specific CVE identifiers have been published at this time; Microsoft has been notified and remediation status is pending public confirmation. Because Copilot functions as an AI agent orchestrating tool use and data retrieval across connected apps, this vulnerability directly demonstrates how a single malicious link can compromise agent-brokered data confidentiality, making it highly relevant to organizations relying on AI agents and copilot-style assistants for cross-application workflows.
Affected Systems
Microsoft Copilot Personal (consumer/personal tier) and its connected third-party or Microsoft 365 personal applications integrated via OAuth or session-based connectors
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published; exploitation relies on a crafted malicious URL/link containing an undocumented Copilot parameter
Remediation Steps
- 1
Apply vendor patch
Monitor Microsoft's security advisories and apply patches or updates to Copilot Personal as soon as they are released.
- 2
Restrict connected app permissions
Review and limit which third-party apps and data sources are connected to Copilot sessions to reduce exposure to exfiltration.
- 3
User awareness training
Educate users on the risks of clicking unsolicited or unfamiliar links, especially those referencing Copilot or Microsoft 365 services.
- 4
Monitor session activity
Enable and review logging/auditing of Copilot session activity and connected app access for anomalous data retrieval patterns.
- 5
Disable unnecessary integrations
Temporarily disconnect non-essential apps from Copilot Personal until the vulnerabilities are confirmed patched.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.