By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Copilot Personal Vulnerabilities Allow Data Exfiltration

Varonis Threat Labs has disclosed three critical vulnerabilities within Microsoft Copilot Personal, collectively named CoSnitch, which could permit unauthorized data exfiltration with a single click. These flaws leverage an undocumented URL parameter that Microsoft Copilot Personal itself surfaced, enabling attackers to silently extract sensitive information from applications connected to the user's Copilot session. The vulnerabilities were detailed in a report by Varonis Threat Labs, highlighting the potential for significant data breaches through a seemingly innocuous interaction.
The CoSnitch vulnerabilities exploit the way Microsoft Copilot Personal handles certain URL parameters, allowing for the injection of malicious code or commands. When a user clicks on a specially crafted link, the vulnerability is triggered, and data accessible to the Copilot instance can be exfiltrated without the user's explicit consent or knowledge. This bypasses standard security measures and user awareness, making it a particularly dangerous threat. The researchers at Varonis Threat Labs demonstrated that the flaws could potentially access data from a wide range of connected applications, depending on the permissions granted to Copilot.
Microsoft Copilot Personal is designed to integrate with various Microsoft applications and services, such as Microsoft 365, to provide users with AI-powered assistance. This integration, while enhancing productivity, also creates a larger attack surface if not properly secured. The vulnerabilities identified by Varonis Threat Labs underscore the inherent risks associated with granting AI assistants broad access to user data and connected services. The ability for a single click to initiate data exfiltration is a significant concern for user privacy and data security, as it requires minimal user interaction and can be easily disguised within phishing or social engineering attacks.
While Varonis Threat Labs has not disclosed the exact technical details of the exploit to prevent immediate widespread abuse, they have confirmed that the vulnerabilities are serious and pose a tangible risk to users. The researchers have been working with Microsoft to address these issues, and it is expected that the company will release patches to mitigate the CoSnitch vulnerabilities. Users are advised to remain vigilant about suspicious links and to ensure their software is up-to-date to benefit from any security fixes implemented by Microsoft. The discovery of CoSnitch highlights the ongoing challenges in securing AI-integrated systems and the importance of continuous security research and development in this rapidly evolving field.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.