< Back to situation

[REVISION HISTORY]

Microsoft Copilot security vulnerabilities

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-18 15:56 UTC → 2026-08-20 20:27 UTC · added removed

Security researchers have identified various ways Microsoft Copilot can be exploited to facilitate cyberattacks and fraud. Initially, Barracuda Networks demonstrated a proof-of-concept for a business email compromise (BEC) attack. In this scenario, attackers use Copilot to map organizational hierarchies, extract financial communications, and draft convincing phishing messages that mimic an employee’s style. This method can lead to the theft of session tokens and the redirection of large wire transfers. Subsequently, researcher Håkon Måløy identified a vulnerability in Microsoft Copilot for Word known as Cross-Prompt Injection Attack (XPIA). This technique involves hiding malicious instructions within documents using nearly invisible formatting, such as white text on a white background. When the AI processes these documents, it executes the hidden commands, which can result in the alteration of financial data or the spread of malicious instructions into newly created documents. In August 2026, Varonis Threat Lab identified a vulnerability chain dubbed ‘CoSnitch’ (CVE-2026-24301). This flaw allowed the AI to inadvertently disclose details regarding its internal architecture and protection mechanisms through targeted questioning. The vulnerability specifically affected the Copilot Personal service, where a single malicious link could potentially trigger unauthorized prompts to read emails, calendars, and files, sending that data to an external server. Microsoft released a full fix on August 18, 2026. Researchers noted no evidence of active exploitation in the wild prior to the patch, and the issue does not appear to affect the Microsoft 365 Copilot enterprise version.

Versions

  1. 2026-08-20 20:27 UTC Microsoft Copilot security vulnerabilities
  2. 2026-08-18 15:56 UTC Microsoft Copilot security vulnerabilities

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.