Varonis Details CoSnitch Flaws Enabling Data Theft Through Microsoft Copilot

· Original article ↗

Summary

Varonis describes CoSnitch, a chain of Microsoft Copilot vulnerabilities that could execute prompts from crafted links, access connected-app data, exfiltrate it, and alter persistent memory. Microsoft patched the flaws on August 18, 2026; Varonis reports no known in-the

Key points

  • Varonis says CoSnitch combines three Microsoft Copilot vulnerabilities, identified as CVE-2026-24301, into an attack chain initiated by a crafted link.
  • A URL parameter could trigger an attacker-supplied prompt to run automatically in a victim’s authenticated Copilot session.
  • Researchers demonstrated that prompts could use connected services such as email, calendars, and cloud drives to retrieve data and send it to an external server.
  • A separate indirect prompt-injection technique could add attacker-controlled instructions to Copilot’s persistent memory through webpage summarization.
  • Varonis says the flaws were disclosed to Microsoft in December 2025 and patched on August 18, 2026; it reports no evidence of exploitation in the wild.
  • Varonis recommends reviewing Copilot connectors and access, scrutinizing links to AI tools, and checking monitoring for unusual data access by Copilot.

Article Details

Attack Vectors
  • A crafted link uses the ?q= and ?autorun=1 parameters to execute an attacker-supplied prompt when Copilot loads in the victim's authenticated session.
  • Prompts can use Copilot's connected apps and URL-fetch capability to retrieve user data and send it to an attacker-controlled webhook.
  • A webpage containing hidden prompt instructions can trigger Copilot to write attacker-controlled content to the user's persistent memory when the page is summarized.
  • Researchers used repeated, reframed questions to persuade Copilot to disclose technical details about its own URL parameters; the article calls this method meta-hacking.
Defensive Notes
  • Audit Copilot connector configurations and remove app connections that are not necessary.
  • Treat Copilot as a privileged insider and apply access reviews and anomaly detection.
  • Review links from external sources that open AI assistants, especially links that pre-fill prompts.
  • Check whether monitoring detects unusual data access originating from Copilot.
  • Users should inspect pre-filled prompts, report unexpected Copilot behavior, and keep connected apps to a minimum.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEeo8el024afgbal3[.]m[.]pipedream[.]netHost shown receiving an example Copilot GET request carrying exfiltrated data.
URLhxxps[:]//knowleadge-base-lion[.]s3[.]us-east-1[.]amazonaws[.]com/data_lion5[.]htmlArticle identifies this specific externally hosted webpage as the prompt-injection proof-of-concept page summarized by Copilot.
URLhxxps[:]//webhook[.]site/75aabb18-9bcf-4383-9e29-349fbc4c40e8/SUPPORTAttacker-directed webhook URL used in the article's example to receive data exfiltrated by Copilot.

MITRE ATT&CK

CVE

Vendors

Products

Related Articles