All posts

Microsoft patches Copilot flaw 8 months after disclosure

Manaal KhanAugust 19, 2026 at 2:16 PM4 min read
Microsoft patches Copilot flaw 8 months after disclosure

Microsoft on Tuesday patched a critical vulnerability in the personal version of Copilot that allowed attackers to exfiltrate user data and permanently poison Copilot's memory with a single malicious link. The fix arrived nearly eight months after security firm Varonis reported the flaw on December 31, 2025.

Microsoft patches Copilot flaw 8 months after disclosure
Source: Computerworld

The vulnerability, dubbed CoSnitch, combined three separate weaknesses into one exploit chain. An attacker could craft a URL that executed prompts automatically on page load, query connected apps like Gmail and OneDrive to steal data, and inject instructions into the victim's permanent memory store. That memory poisoning survived password changes, session revocations, and device re-enrollment.

8 months
Time between Varonis reporting the CoSnitch flaw and Microsoft completing the fix
Advertisements

How Copilot revealed its own weakness

A Critical Microsoft 365 Copilot Flaw Just Dropped (And There’s Nothing to Patch)

The most striking detail: Copilot essentially mapped the attack path itself. Varonis researchers prompted Copilot to explain why automatic execution was impossible. Each refusal came with technical justification that mapped the architecture.

We reframed every refusal as a follow-up question, and each answer narrowed the attack surface further. Copilot then disclosed an undocumented URL parameter, unprompted, mid-refusal, including its historical behavior and every protection put in place to disable it. We built the URL exactly as described.

— Varonis security researchers

The researchers didn't breach Copilot. They played it. This method of extracting vulnerability information from an LLM's own defensive explanations represents a new class of social engineering, one that treats the AI itself as an unwitting insider.

Also Read
Researchers tricked Copilot into revealing its own flaws

Earlier coverage of Varonis's Copilot research methodology

Microsoft's fragmented response

Microsoft's patching timeline was uneven. The company addressed the auto-execution capability on February 1, roughly a month after disclosure. But the full fix didn't land until Tuesday. The February patch "lowered the other vulnerabilities significantly," according to Lior Adar, a Varonis senior security researcher.

Microsoft confirmed the flaw and the fix. "Our customers are already protected and do not need to take any action," the company said. It labeled the hole "critical" in its MSRC disclosure.

CoSnitch marks the third Copilot bug Varonis has reported to Microsoft this year. The prior two, Reprompt and SearchLeak, shared the same exploit pattern: one click on a legitimate-looking link is all it takes. Reprompt bypassed Copilot guardrails by repeating queries. SearchLeak, Varonis claimed, turned Microsoft 365 Copilot Enterprise into "a silent exfiltration tool."

The enterprise exposure Microsoft downplayed

Microsoft's statement that "enterprise customers using Microsoft 365 Copilot are not affected" isn't strictly accurate. Enterprise environments routinely contain personal-grade Copilot instances from employee personal accounts. A flaw in the personal version can absolutely reach enterprise data through those mixed deployments.

This matters more now because Microsoft is merging its Copilot products. The company confirmed it "is in the process of moving toward a more unified Copilot experience" called Copilot Fusion. Details began leaking last month. Enterprise CISOs need to watch whether flaws in the personal version carry over into the merged offering.

Also Read
AI-found vulnerabilities see same 1.3% exploit rate as human finds

Context on AI vulnerability discovery and exploit rates

What the attack chain tells security teams

Mark Tauschek, VP and distinguished analyst at Info-Tech Research Group, called the Varonis methodology "very concerning in its capability." The combination of social engineering on an LLM, jailbreaks, and prompt injection "is what makes it more startling," he said. "We've seen all of those methods alone before, but I think all three working for one exploit is new, at least from a disclosure perspective."

Chen Levy Ben Aroy, the Varonis Cloud Security Research Team leader, put it bluntly: "LLMs are a whole new world of vulnerabilities." The core problem is that LLMs cannot distinguish data in a query from an instruction. Until that changes architecturally, prompt injection will remain a systemic weakness.

ℹ️

Logicity's Take

Eight months to patch a critical flaw is a long time when AI assistants have access to email, calendars, and cloud drives. Microsoft's claim that enterprise users weren't affected sidesteps the reality of mixed deployments. With Copilot Fusion merging personal and enterprise versions, CISOs should treat personal-tier vulnerabilities as enterprise risks now, not after the merger ships.

The CoSnitch disclosure should accelerate internal reviews of which AI tools have access to what data, and what authentication boundaries actually exist between personal and enterprise accounts. The one-click attack pattern isn't going away.

ℹ️

Need Help Implementing This?

Logicity helps IT teams audit AI tool deployments and map data exposure risks. Reach us at consulting@logicity.in to discuss your Copilot rollout or AI security posture.

Source: Computerworld

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.