Copilot revealed its own hack — Microsoft patches after 8 months
One click was enough: a hidden URL parameter let Copilot Personal leak mail, calendar, and Drive data. Reported in December — fixed now.

Illustration · AI-generated (AI IN LIFE)
At a glance
- Three chained flaws, tracked together as CVE-2026-24301
- Reported: December 2025; patched: August 18, 2026 — about 8 months later
- One-click attack via undocumented autorun=1 parameter
- Exposed: mail, calendar, Drive file names, chat history, saved instructions
- No evidence of in-the-wild exploitation
What happened? On August 18, Microsoft closed three chained vulnerabilities in Copilot Personal that Varonis security researchers had reported under the name "CoSnitch" (CVE-2026-24301) — back in December 2025. Roughly eight months passed between report and full patch.
How did the attack work? A single click on a legitimate-looking link sufficed. An undocumented URL parameter called autorun=1 executed an embedded prompt instruction without user confirmation. That allowed data to be pulled from connected services — email bodies including plaintext credentials, calendar entries, file names from Google Drive, and the Copilot chat history. "One click on a legitimate-looking link is enough," as the Varonis researchers put it.
What makes the case special? The discovery method. The researchers did not hack Copilot in the classic sense — they kept questioning the assistant about its own safety logic until it disclosed the secret parameter itself. "Copilot wasn't breached; it was played," says Varonis researcher Lior Adar. A third component: crafted websites could permanently poison Copilot's long-term memory — the manipulation even survived password rotation and device re-enrollment.
How is Microsoft responding? The company stresses that Copilot does not expand permissions: connected services operate within existing account access. Both sides say there is no evidence of active exploitation. The patches are rolled out server-side; users need to do nothing.
What's the lesson? AI assistants with account access are a new attack target with old weaknesses — and the models' own eagerness to explain becomes a reconnaissance tool for attackers. Anyone connecting Copilot, Gemini, and peers to mail and calendar should review connected services regularly and keep an eye on memory features.
This article was produced with AI assistance and editorially reviewed.
FAQ
Do Copilot users need to act now?
No, the patches apply server-side. Still, reviewing connected services and saved Copilot memories is a sensible habit.
Were Microsoft 365 business accounts affected?
The described attack targeted Copilot Personal (copilot.microsoft.com). Microsoft 365 Copilot has separate protections, according to Microsoft.
Was the flaw actively exploited?
Neither Varonis nor Microsoft found evidence of in-the-wild exploitation — though proving a negative is never fully possible.


