Microsoft patched consumer-facing Copilot on August 18, 2026 for CVE-2026-24301, a high-severity flaw rated 8.8 out of 10. Varonis linked it to CoSnitch, a three-step attack chain.
According to Varonis, one click on a crafted Copilot link that used an undocumented autorun parameter, for example `https://copilot.microsoft.com/?q=&autorun=1…`, could automatically fire off a prompt. That gave an attacker a way to pull data you’d already shared in that session. And if you’d connected other services, Varonis said the same method could also potentially expose email addresses, secrets and passwords in messages, Drive files, and calendar details.
The researchers say they found the issue by “meta-hacking” Copilot: asking over and over about its refusals, safety rules, and guardrails until it exposed the undocumented route. Varonis also said the chain involved persistent memory poisoning, where malicious instructions could keep shaping later behavior.
If you use Copilot with connected apps, you should install the fix, check which services are linked, remove anything you don’t need, and be careful with unexpected Copilot links. Microsoft said it found no evidence that the flaw was being exploited in the wild.
Varonis said it reported the issue in December 2025, Microsoft patched it on August 18, 2026, and the fix is now live in consumer-facing Copilot Personal.