Varonis Details CoSnitch Flaws Enabling Data Theft Through Microsoft Copilot

Summary
Varonis describes CoSnitch, a chain of Microsoft Copilot vulnerabilities that could execute prompts from crafted links, access connected-app data, exfiltrate it, and alter persistent memory. Microsoft patched the flaws on August 18, 2026; Varonis reports no known in-the
Key points
- Varonis says CoSnitch combines three Microsoft Copilot vulnerabilities, identified as CVE-2026-24301, into an attack chain initiated by a crafted link.
- A URL parameter could trigger an attacker-supplied prompt to run automatically in a victim’s authenticated Copilot session.
- Researchers demonstrated that prompts could use connected services such as email, calendars, and cloud drives to retrieve data and send it to an external server.
- A separate indirect prompt-injection technique could add attacker-controlled instructions to Copilot’s persistent memory through webpage summarization.
- Varonis says the flaws were disclosed to Microsoft in December 2025 and patched on August 18, 2026; it reports no evidence of exploitation in the wild.
- Varonis recommends reviewing Copilot connectors and access, scrutinizing links to AI tools, and checking monitoring for unusual data access by Copilot.
Article Details
- Attack Vectors
- A crafted link uses the ?q= and ?autorun=1 parameters to execute an attacker-supplied prompt when Copilot loads in the victim's authenticated session.
- Prompts can use Copilot's connected apps and URL-fetch capability to retrieve user data and send it to an attacker-controlled webhook.
- A webpage containing hidden prompt instructions can trigger Copilot to write attacker-controlled content to the user's persistent memory when the page is summarized.
- Researchers used repeated, reframed questions to persuade Copilot to disclose technical details about its own URL parameters; the article calls this method meta-hacking.
- Defensive Notes
- Audit Copilot connector configurations and remove app connections that are not necessary.
- Treat Copilot as a privileged insider and apply access reviews and anomaly detection.
- Review links from external sources that open AI assistants, especially links that pre-fill prompts.
- Check whether monitoring detects unusual data access originating from Copilot.
- Users should inspect pre-filled prompts, report unexpected Copilot behavior, and keep connected apps to a minimum.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | eo8el024afgbal3[.]m[.]pipedream[.]net | Host shown receiving an example Copilot GET request carrying exfiltrated data. |
| URL | hxxps[:]//knowleadge-base-lion[.]s3[.]us-east-1[.]amazonaws[.]com/data_lion5[.]html | Article identifies this specific externally hosted webpage as the prompt-injection proof-of-concept page summarized by Copilot. |
| URL | hxxps[:]//webhook[.]site/75aabb18-9bcf-4383-9e29-349fbc4c40e8/SUPPORT | Attacker-directed webhook URL used in the article's example to receive data exfiltrated by Copilot. |
MITRE ATT&CK
CVE
Vendors
MicrosoftVaronis Threat Labs uncovered another one-click vulnerability in Microsoft Copilot Personal dubbed CoSnitch (critical, CVE-2026-24301), which quietly executes an attack chain that exfiltrates data from enterprisesVaronisVaronis Threat Labs uncovered another one-click vulnerability in Microsoft Copilot Personal dubbed CoSnitch (critical, CVE-2026-24301), which quietly executes an attack chain that exfiltrates data from enterprises
Products
GmailData exfiltration to external servers: An injected prompt can query the victim's connected apps (Gmail, Drive, Calendar, OneDrive), encode the results into a URL, and exfiltrate them via Copilot's built-in URL-fetchGoogle CalendarGet my Google Calendar events for the next 14 days - include titles, attendees, and locationsGoogle DriveWhen enterprise users connect third-party services to Copilot (Gmail, Google Drive, Calendar, etc.) they grant OAuth tokens scoped to specific permissions.Microsoft 365 Copilot EnterpriseSearchLeak turned Microsoft 365 Copilot Enterprise into a silent exfiltration tool.Microsoft Copilot PersonalVaronis Threat Labs uncovered another one-click vulnerability in Microsoft Copilot Personal dubbed CoSnitch (critical, CVE-2026-24301), which quietly executes an attack chain that exfiltrates data from enterprisesOneDriveto external servers: An injected prompt can query the victim's connected apps (Gmail, Drive, Calendar, OneDrive), encode the results into a URL, and exfiltrate them via Copilot's built-in URL-fetch capability to anOutlookGmail / Outlook