Microsoft patches critical Copilot flaw CoSnitch: one click siphons data from linked accounts

emmanuelvivier · x · 2026-08-20

Microsoft has patched critical Copilot Personal vulnerability CVE-2026-24301, nicknamed CoSnitch, which let attackers silently exfiltrate sensitive data from a victim's connected accounts (e.g., Gmail) with a single click on a malicious link.

Discovered by Varonis Threat Labs, the flaw chained three weaknesses: an undocumented URL parameter combined with Copilot's ?q= query parameter executed an attacker-crafted prompt automatically on page load—no click or confirmation needed—after which Copilot could query and exfiltrate data from the victim's linked apps.

It's the third Copilot vulnerability Varonis has found this year, after Reprompt (bypassing safety guardrails by asking twice) and SearchLeak (turning Microsoft 365 Copilot Enterprise into a covert exfiltration channel). All share the same trait: a single innocuous-looking click triggers the chain with no warning signs.

Related event: Microsoft Patches Copilot Flaw That Let One Click Steal Gmail and Drive Data(2 posts)→

Original post →

More from Safety

Safety channel →