highZero-Day

CoSnitch – Microsoft Copilot Personal One-Click Data Exfiltration Flaws

First seen Aug 19, 2026 · Updated Aug 19, 2026

microsoft-copilotLLM-vulnerabilityone-click-exploitdata-exfiltrationprompt-injectionagent-relevantai-security

Varonis Threat Labs disclosed three vulnerabilities, collectively named CoSnitch, in Microsoft Copilot Personal that could allow an attacker to exfiltrate data from a victim's connected apps and Copilot session with a single click on a crafted link. The flaws exploit an undocumented URL parameter surfaced by the assistant itself, enabling silent data leakage without further user interaction.

Technical Analysis

The CoSnitch vulnerabilities abuse an undocumented URL parameter within Microsoft Copilot Personal that the assistant exposes, allowing a maliciously crafted link to trigger unauthorized queries against the victim's active Copilot session. Because Copilot integrates with connected applications (e.g., email, files, calendar), a successful exploit can silently pull sensitive data accessible to the LLM's context without additional clicks or explicit consent. This class of flaw highlights broader risks in agentic and RAG-style architectures where a conversational assistant is granted persistent access to multiple connected data sources under an implicit trust boundary. No specific CVE identifiers have been published at this time; Microsoft has been notified and remediation status is pending public confirmation. Because Copilot functions as an AI agent orchestrating tool use and data retrieval across connected apps, this vulnerability directly demonstrates how a single malicious link can compromise agent-brokered data confidentiality, making it highly relevant to organizations relying on AI agents and copilot-style assistants for cross-application workflows.

Affected Systems

Microsoft Copilot Personal (consumer/personal tier) and its connected third-party or Microsoft 365 personal applications integrated via OAuth or session-based connectors

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published; exploitation relies on a crafted malicious URL/link containing an undocumented Copilot parameter

Remediation Steps

  1. 1

    Apply vendor patch

    Monitor Microsoft's security advisories and apply patches or updates to Copilot Personal as soon as they are released.

  2. 2

    Restrict connected app permissions

    Review and limit which third-party apps and data sources are connected to Copilot sessions to reduce exposure to exfiltration.

  3. 3

    User awareness training

    Educate users on the risks of clicking unsolicited or unfamiliar links, especially those referencing Copilot or Microsoft 365 services.

  4. 4

    Monitor session activity

    Enable and review logging/auditing of Copilot session activity and connected app access for anomalous data retrieval patterns.

  5. 5

    Disable unnecessary integrations

    Temporarily disconnect non-essential apps from Copilot Personal until the vulnerabilities are confirmed patched.

Industries Most Exposed

technologyfinancial serviceshealthcareeducationgovernmentall industries using Microsoft 365 Personal/Copilot

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.