One Link Was Enough to Empty Your Copilot, and the Fix Took Eight Months
Microsoft patched CVE-2026-24301 on 18 August. Varonis calls it CoSnitch: a single click on a crafted link made Copilot read a victim's Gmail, Drive and Calendar and send the contents to a stranger.
Microsoft shipped a patch on 18 August for a critical flaw in Copilot Personal that researchers at Varonis Threat Labs named CoSnitch. Rated 8.8 out of 10 and tracked as CVE-2026-24301, it did something uncomfortably simple: one click on a normal-looking link was enough for an attacker to read whatever the victim’s Copilot could reach, and quietly ship it out. Varonis reported the problem in December 2025. The full fix arrived roughly eight months later.
The attack chained three separate weaknesses. First, an undocumented URL parameter meant a prompt embedded in a link would run the moment the page loaded, with no click on a send button and no confirmation. Second, that prompt inherited the victim’s already logged-in session, so it could query anything the user had connected: Gmail, Google Drive, Calendar, Copilot’s chat history and Copilot’s memory. Third, Copilot’s ordinary ability to fetch and summarise a web page became the delivery van. The prompt packed the collected data into a web address and asked Copilot to fetch it, so the theft looked, on the network, exactly like Copilot fetching any other link.
There is a third weakness worth its own paragraph, because it is the one that lasts. Varonis showed that a booby-trapped web page, when summarised by Copilot, could write attacker instructions into Copilot’s permanent memory. That is known as indirect prompt injection: the malicious instruction lives inside content the assistant reads on your behalf, not in something you typed. The victim sees a perfectly normal summary. The instruction stays. It survives password changes, session revocation and re-enrolling the device, because it is stored in the assistant’s memory rather than in a session. Varonis found no sign the attack was used in the wild before the patch.
The discovery method is its own story. The researchers did not reverse engineer anything. They kept asking Copilot to explain why automatic prompt execution was impossible, and each refusal came with a technical justification that narrowed the search a little further. Eventually the assistant named the undocumented parameter itself, mid-refusal. Varonis calls this meta-hacking, and it is the part that generalises beyond Microsoft: any assistant that explains its own reasoning in plain language can be talked into describing its own edges.
What this means for you: if you use Copilot Personal, apply updates and then go and look at Copilot’s memory settings, because a poisoned memory entry would still be sitting there. It is a page almost nobody opens. Beyond that, the durable lesson is about connectors. Every service you link to an AI assistant widens what a single bad click can reach, so connect only what you actually use and disconnect the rest. And treat any link that pre-fills a prompt in an AI tool the way you would treat an unexpected attachment: read what it says before it runs. This is the third one-click Copilot flaw Varonis has published this year, which suggests the pattern is not finished.
Sources
Europe's Next AI Data Centres Are Being Built 175 Kilometres From Anywhere, Because That Is Where the Power Is
JLL figures show Europe's coming AI data centres will sit an average 175km from major hubs, up from 46km for 2022 to 2025 projects. Powered land in Amsterdam costs 2.36 million euros per megawatt against 512,000 elsewhere.