Microsoft has patched a critical security flaw in the consumer version of Copilot that allowed attackers to access personal data through a single link. This update matters because the vulnerability, tracked as CVE-2026-24301, enabled unauthorized execution of commands without any user interaction. Users relying on the assistant for daily tasks now have a confirmed fix for a risk that exposed their digital identity.
Critical vulnerability allowed attackers to access personal data through a single link
The vulnerability, which Varonis Threat Labs named CoSnitch, exploited an undocumented address bar parameter within the Copilot interface. Researchers demonstrated the attack by sending a malicious link that triggered the flaw on the server side. This mechanism bypassed the need for a user to click or confirm any action, making the exploit particularly dangerous for active users.
Security experts rated the flaw with a CVSS score of 8.8 out of 10, classifying it as critical. The exploit granted attackers access to the user's inbox, calendar, cloud drive, and long-term memory stored within Copilot. Microsoft addressed the issue through server-side updates, closing the gap that allowed such deep data exposure.
The vulnerability was originally reported to Microsoft in December 2025. The company took eight months to deploy the fix, which Microsoft MSRC has now confirmed as resolved. This timeline highlights the complexity of securing AI assistants that process sensitive personal information across multiple services.
Source: Microsoft Copilot, NotebookCheck




Discussion
0 comments