Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs disclosed CoSnitch, a set of three flaws in Microsoft Copilot Personal that could let a crafted link trigger silent prompt execution and exfiltrate data from connected apps in a victim’s authenticated session. The research also showed a separate memory-poisoning path through web summarization, and Microsoft shipped patches for CVE-2026-24301 on August 18, 2026. #CopilotPersonal #CoSnitch #CVE-2026-24301 #Microsoft

Keypoints

  • Varonis found three vulnerabilities in Microsoft Copilot Personal.
  • A crafted link could trigger attacker-supplied prompts without user interaction.
  • The attack could steal data from connected services like email, Drive, chat history, and memory.
  • A separate flaw could poison Copilot memory through a summarized web page.
  • Microsoft fixed the issue and assigned it CVE-2026-24301.

Read More: https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html