Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Broken Clouds Humidity: 58%
Wind: 2.57 M/S

Data From Connected Apps at Risk Due to Microsoft Copilot Personal Vulnerabilities

Data From Connected Apps at Risk Due to Microsoft Copilot Personal Vulnerabilities

Researchers at Varonis Threat Labs have disclosed three security vulnerabilities in Microsoft Copilot Personal that could allow attackers to extract data from connected applications with a single click. Collectively dubbed CoSnitch, the vulnerabilities could enable unauthorized access to information available within a victim's active Copilot session.

According to Varonis, the attack chain relies in part on an undocumented URL parameter that the researchers discovered during testing after repeatedly questioning Copilot about ways to execute prompts automatically without user interaction. The assistant eventually revealed a parameter called autorun=1, along with details about how it was intended to function and the protections that were supposed to prevent abuse.

Varonis reported the vulnerabilities to Microsoft in December 2025, and Microsoft released fixes on August 18, 2026. The issue is tracked as CVE-2026-24301 in Microsoft's Security Update Guide.

The research specifically targets the consumer-focused version of Copilot hosted at copilot.microsoft.com. Varonis did not indicate that the same behavior affected Microsoft 365 Copilot. The company also stated that it found no evidence that the vulnerabilities had been exploited in real-world attacks.

When researchers recreated the URL exactly as Copilot described, they found that the supposedly disabled functionality still worked. Varonis noted that Copilot itself was not compromised but rather manipulated into revealing internal implementation details.

The attack combines the hidden autorun=1 parameter with Copilot's existing q parameter. While the q parameter normally prepopulates the prompt field, Varonis found that pairing it with autorun=1 causes an attacker-supplied prompt to execute automatically as soon as the page loads, without requiring any user action. Once triggered, the prompt continues running even if the victim closes the browser tab immediately afterward.

Three Vulnerabilities Identified

Varonis grouped the findings into three separate but related vulnerabilities:

1. Automatic Prompt Execution

The combination of URL parameters allows attacker-controlled prompts to execute automatically within a victim's authenticated Copilot session. The prompt runs with the same privileges and capabilities as if the victim had entered it manually.

2. Data Exfiltration Through Connected Apps

The malicious prompt can access data from services that the user has already connected and authorized within Copilot. It can then encode the retrieved information and transmit it to an attacker-controlled endpoint using Copilot's built-in web-fetching functionality.

Importantly, this technique does not expand the user's permissions or grant access to additional services. Instead, it abuses access already authorized by the user.

During testing, researchers were able to retrieve:

  • Email subjects and message contents
  • Sender and recipient details
  • Calendar titles, attendees, locations, and schedules
  • Google Drive file names and metadata summaries
  • Previous Copilot conversation history
  • Stored memory entries and custom instructions

Microsoft's documentation states that connected services operate strictly under the user's existing permissions and that Copilot can only access content the user is already authorized to view.

Varonis further noted that the outbound traffic generated by the attack appears nearly identical to the network requests Copilot normally makes when summarizing webpages. The researchers said attackers could also use Base64 encoding to help conceal sensitive information within outbound requests.

3. Persistent Memory Poisoning

The third vulnerability involves Copilot's memory feature. Researchers found that a specially crafted webpage, when summarized by Copilot, could inject malicious instructions into the user's memory store.

These implanted instructions could influence future Copilot interactions and remain active even after:

  • Password changes
  • Session revocations
  • Device re-enrollment

According to Varonis, the malicious memory persists until the user manually removes it from Copilot's memory settings.

The researchers also claimed that these memory modifications generate no obvious security alerts, logs, processes, or network indicators that conventional security tools would typically detect. The changes are only visible within Copilot's memory interface.

Previous Research Into Copilot Memory Risks

The CoSnitch findings are not the first reports involving manipulation of Copilot memory.

Security researcher Håkon Måløy previously demonstrated a method of creating unintended memory entries through a Microsoft 365 Copilot summarization workflow. The research was published on June 22, 2026, after a coordinated disclosure process. Microsoft later stated that the issue had been mitigated globally.

Researcher Johann Rehberger also reported memory manipulation techniques involving indirect prompt injection, including the ability to create, modify, and delete memory entries in both Microsoft 365 Copilot and the consumer Copilot product. That work was associated with CVE-2026-24299.

In a June 2026 security blog, Microsoft said Microsoft 365 Copilot uses multiple safeguards, including:

  • Prompt-injection detection
  • Memory sanitization during writes
  • Task-adherence validation checks
  • Audit logging of memory modifications
  • Security visibility through Defender Advanced Hunting and Microsoft Sentinel

Mitigation and Recommendations

Varonis advised users and organizations to:

  • Review and limit applications connected to Copilot
  • Disconnect services that are no longer necessary
  • Treat AI assistants as high-privilege applications during access reviews
  • Monitor for unusual activity involving connected services
  • Exercise caution when opening links that launch AI assistant sessions

The researchers noted that users do not need to install a separate client update, as Microsoft's fixes have already been deployed. However, Varonis warned that any malicious memory entries created before the remediation may remain in place until manually removed, and the disclosure does not specify whether Microsoft has retroactively cleaned up affected memory stores.

The research follows Varonis' recent disclosure of RovoBlast, a one-click attack targeting Atlassian's Rovo assistant. That attack abused the rovoChatPrompt URL parameter to inject malicious instructions into authenticated user sessions. Atlassian reportedly fixed the issue before public disclosure.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.