ANDROID Vivo V70 Lite 4G Adds 8,100mAh Battery, Drops 5G for Unisoc Chip STEAM Phantom Blade Zero Pre-Orders Hit 300K, Chasing Black Myth: Wukong INTEL Asus CX9406 Googlebook Leak: Panther Lake CPU, 16GB RAM, $1,383 Price GAMES GTA 6 Leaked Footage Shows Driving and Strip Club Scenes CONSOLES The Duskbloods Switch 2 Input Lag Hits 200ms in Network Test PC HARDWARE Philips Evnia 27-inch 260Hz Monitor Launches for $190 GAMES GTA 6 Leaks Hit Rockstar Morale, Netflix Unfazed by Early Footage AMD AMD Desktop CPU Share Hits 34.9% in Q2 2026 as Intel Loses Ground GAMES WWE 2K26 Patch 1.15 Adds Finn Balor Theme and Fixes Match Bugs NVIDIA Modern Warfare 4 Beta Nerfs Frangible Rounds and Footsteps GAMES Modern Warfare 4 Beta Patch Tweaks TTK and Footstep Audio SOFTWARE AND UPDATES Twitch Faces Class Action Lawsuit Over Unlicensed AI Training INTEL Lenovo ThinkPad L14 Gen 7 Launches with Wi-Fi 7 and Core Ultra 3 for $1,109 STEAM Settler’s Domain Launches on Steam With Native ARM Support

Microsoft Patches Critical Copilot Flaw That Exposed User Data

Lena Fischer 0 comments 2 min read

Microsoft has patched a critical security flaw in Copilot (CVE- 2026- 24301) that allowed attackers to access user data without interaction.

Microsoft Patches Critical Copilot Flaw That Exposed User Data
SOFTWARE AND UPDATES

Microsoft has patched a critical security flaw in the consumer version of Copilot that allowed attackers to access personal data through a single link. This update matters because the vulnerability, tracked as CVE-2026-24301, enabled unauthorized execution of commands without any user interaction. Users relying on the assistant for daily tasks now have a confirmed fix for a risk that exposed their digital identity.

Critical vulnerability allowed attackers to access personal data through a single link

The vulnerability, which Varonis Threat Labs named CoSnitch, exploited an undocumented address bar parameter within the Copilot interface. Researchers demonstrated the attack by sending a malicious link that triggered the flaw on the server side. This mechanism bypassed the need for a user to click or confirm any action, making the exploit particularly dangerous for active users.

Security experts rated the flaw with a CVSS score of 8.8 out of 10, classifying it as critical. The exploit granted attackers access to the user's inbox, calendar, cloud drive, and long-term memory stored within Copilot. Microsoft addressed the issue through server-side updates, closing the gap that allowed such deep data exposure.

The vulnerability was originally reported to Microsoft in December 2025. The company took eight months to deploy the fix, which Microsoft MSRC has now confirmed as resolved. This timeline highlights the complexity of securing AI assistants that process sensitive personal information across multiple services.

Source: Microsoft Copilot, NotebookCheck

Discussion

0 comments

Leave a comment