Microsoft Copilot revealed its own flaw, one link read your inbox

Researchers at Varonis got Microsoft's AI assistant Copilot to hand over its own weak spot. They kept asking why a command could not run on its own. Copilot explained the reasoning behind every refusal. Mid-refusal, it named an undocumented parameter for the address bar, along with the safeguards Microsoft had put around it. The researchers built the address exactly as described. It worked.
Microsoft closed the hole on 18 August. It is tracked as CVE-2026-24301 and rated critical, with a CVSS score of 8.8 out of 10. CVSS is the industry's standard scale for how severe a security flaw is. The affected product was Copilot in its consumer version, the app Microsoft recently merged with the subscription tier.
One click, and the assistant worked for strangers
The attack, which Varonis named CoSnitch, needed nothing but a link. Clicking it opened Copilot inside the victim's own signed-in session. The extra parameter in the address made an attacker's instruction run straight away, with no prompt and no press of the send button. Copilot then searched the connected inbox, the calendar and the cloud drive, packed what it found into a web address and fetched it. To the security tools watching the network, that looked like an ordinary page Copilot had been asked to summarise.
In the researchers' tests this pulled out passwords that someone had simply emailed over. Along with meetings including attendees and locations, file names from the cloud drive and the earlier chat history.
Why a new password did not help
The nastiest part sits in long-term memory. Copilot remembers things beyond a single conversation. Ask it to summarise a booby-trapped web page and it wrote the instructions hidden there into that memory. To the user, the reply looked like an ordinary summary. That an assistant can be fed instructions this way is not a new discovery.
The entry then stayed put. A new password did not clear it, signing out of every session did not either, and re-enrolling the device made no difference. Those three steps are exactly what people do when they suspect someone has been in their account.
What you can check now
Microsoft fixed the flaw on its own servers, so nobody has to install anything. Varonis found no sign that anyone actually used the attack. It was reported in December 2025 and the fix landed eight months later.
If you want to look anyway: on copilot.microsoft.com the account button in the sidebar leads to the stored memory. Every entry is listed there, and you can delete them one by one or all at once. Anything that does not belong tends to stand out on a first read.
CoSnitch is the third Copilot flaw Varonis has found this year. The other two followed the same pattern: one click on a link that looked harmless.





