Varonis Threat Labs disclosed CoSnitch, a set of three flaws in Microsoft Copilot Personal that could let a crafted link trigger silent prompt execution and exfiltrate data from connected apps in a victim’s authenticated session. The research also showed a separate memory-poisoning path through web summarization, and Microsoft shipped patches for CVE-2026-24301 on August 18, 2026. #CopilotPersonal #CoSnitch #CVE-2026-24301 #Microsoft
Keypoints
- Varonis found three vulnerabilities in Microsoft Copilot Personal.
- A crafted link could trigger attacker-supplied prompts without user interaction.
- The attack could steal data from connected services like email, Drive, chat history, and memory.
- A separate flaw could poison Copilot memory through a summarized web page.
- Microsoft fixed the issue and assigned it CVE-2026-24301.
Read More: https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html