< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

Microsoft Copilot vulnerability ‘CoSnitch’ patched after researchers exploit AI defenses

Security researchers at Varonis Threat Lab have identified a vulnerability chain in Microsoft Copilot, dubbed ‘CoSnitch’ (CVE-2026-24301), which allowed the AI to inadvertently reveal information about its own defenses.

By asking a series of targeted questions, researchers were able to prompt the chatbot to disclose details regarding its internal architecture and protection mechanisms. This information could theoretically be used to bypass security filters. The vulnerability specifically affected the Copilot Personal service, where a single malicious link could potentially trigger unauthorized prompts to read emails, calendars, and files, subsequently sending that data to an external server.

Microsoft has since released a full fix, with patches distributed as of August 18, 2026. While the vulnerability was demonstrated on the personal version of the service, researchers noted that they found no evidence of active exploitation in the wild prior to the patch. The issue does not appear to affect the Microsoft 365 Copilot enterprise version.

Entities

Copilot · Google · Microsoft · OpenAI · Varonis