STEAM Silicone Heart Demo Released on Steam After Kickstarter Failure, Sets December 2026 Launch GAMES Escape from Tarkov adds direct ruble microtransactions and a 5% XP referral bonus PLAYSTATION 5 Former Naughty Dog Developer Praises GTA San Andreas $600 Million Revenue Without Microtransactions AMD AMD to release lightweight FSR 4 for handhelds and gaming laptops by year-end PLAYSTATION 5 Hazard Levels leaves Early Access and launches globally on November 12 for PS5, Xbox Series, and PC SOFTWARE AND UPDATES Windows 11 Search becomes a system hub with voice commands to toggle Bluetooth and Dark mode GAMES Japanese man files for bankruptcy after 2 million yen in gacha game debt NVIDIA Microsoft launches Surface RTX Spark Dev Box with 128 GB unified memory for $5,999 SOFTWARE AND UPDATES Community tool unlocks continuous autofocus on Hasselblad X2D and 907X cameras XBOX SERIES X GTA 6 missions let players ignore optimal escape routes during police chases PLAYSTATION 5 Sonic Racing CrossWorlds adds Avatar Legends Pack with Aang and Katara on October 14 PLAYSTATION 5 BrokenLore: ASCEND launches January 7, 2027 on PlayStation 5, Xbox Series, and PC GAMES Halo Campaign Evolved to receive Firefight and Theater modes in winter update GAMES The Coalition Promises Next Gears of War Won’t Take Seven Years to Develop

Microsoft Patches Critical Copilot Flaw That Exposed User Data

Lena Fischer 2 min read

Microsoft has patched a critical security flaw in Copilot (CVE- 2026- 24301) that allowed attackers to access user data without interaction.

Microsoft Patches Critical Copilot Flaw That Exposed User Data
SOFTWARE AND UPDATES

Microsoft has patched a critical security flaw in the consumer version of Copilot that allowed attackers to access personal data through a single link. This update matters because the vulnerability, tracked as CVE-2026-24301, enabled unauthorized execution of commands without any user interaction. Users relying on the assistant for daily tasks now have a confirmed fix for a risk that exposed their digital identity.

Critical vulnerability allowed attackers to access personal data through a single link

The vulnerability, which Varonis Threat Labs named CoSnitch, exploited an undocumented address bar parameter within the Copilot interface. Researchers demonstrated the attack by sending a malicious link that triggered the flaw on the server side. This mechanism bypassed the need for a user to click or confirm any action, making the exploit particularly dangerous for active users.

Security experts rated the flaw with a CVSS score of 8.8 out of 10, classifying it as critical. The exploit granted attackers access to the user's inbox, calendar, cloud drive, and long-term memory stored within Copilot. Microsoft addressed the issue through server-side updates, closing the gap that allowed such deep data exposure.

The vulnerability was originally reported to Microsoft in December 2025. The company took eight months to deploy the fix, which Microsoft MSRC has now confirmed as resolved. This timeline highlights the complexity of securing AI assistants that process sensitive personal information across multiple services.

Source: Microsoft Copilot, NotebookCheck