Microsoft Copilot Personal one-click prompt execution and exfiltration flaw (CVE-2026-24301)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft Copilot Personal CoSnitch vulnerabilities in CVE-2026-24301 let a crafted link trigger prompt execution inside an authenticated session and quietly pull data from connected apps. Microsoft said patches shipped on August 18, 2026, while Varonis found no evidence of exploitation in the wild. The issue affects the consumer assistant at copilot.microsoft.com and hinges on the autorun=1 and q parameters.
Related Happenings
Microsoft 365 Copilot Word hidden-instruction prompt injection security flaw
Vulnerability
H score0
First: 30.07.2026 14:54
Last: 30.07.2026 14:54
Sources 1
About this happening:
Microsoft 365 Copilot for Word remains vulnerable to hidden-instruction prompt injection that can rewrite report figures and copy malicious instructions into the finished...
Microsoft 365 Copilot Word hidden-instruction prompt injection security flaw
VulnerabilityAbout this happening: Microsoft 365 Copilot for Word remains vulnerable to hidden-instruction prompt injection that can rewrite report figures and copy malicious instructions into the finished...
Microsoft expands Purview DLP enforcement for Copilot across local and cloud Office files
Security Tool/Service
H score11
First: 24.02.2026 19:30
Last: 24.02.2026 19:30
Sources 1
About this happening:
Microsoft is expanding Purview DLP so Microsoft 365 Copilot cannot process restricted Word, Excel, and PowerPoint files stored on local devices, SharePoint, or OneDr...
Microsoft expands Purview DLP enforcement for Copilot across local and cloud Office files
Security Tool/ServiceAbout this happening: Microsoft is expanding Purview DLP so Microsoft 365 Copilot cannot process restricted Word, Excel, and PowerPoint files stored on local devices, SharePoint, or OneDr...
Microsoft Copilot Reprompt prompt-injection security flaw
Vulnerability
H score0
First: 14.01.2026 16:00
Last: 14.01.2026 16:00
Sources 1
About this happening:
Reprompt is a Microsoft Copilot prompt-injection flaw that can let a crafted URL trigger invisible data exfiltration from an authenticated session. The abuse path...
Microsoft Copilot Reprompt prompt-injection security flaw
VulnerabilityAbout this happening: Reprompt is a Microsoft Copilot prompt-injection flaw that can let a crafted URL trigger invisible data exfiltration from an authenticated session. The abuse path...
Timeline
-
18.08.2026 20:47 2 articles · 2h ago
Varonis discloses CoSnitch vulnerabilities in Microsoft Copilot Personal
Initial DisclosureVaronis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch and tracked as CVE-2026-24301, describing a crafted-link path that can trigger prompt execution inside an authenticated Copilot session and pull data from connected apps and session information; the company also said Microsoft patches shipped on August 18, 2026 and that it found no evidence of in-the-wild exploitation.
Show sources
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps — thehackernews.com — 18.08.2026 20:47
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps — thehackernews.com — 18.08.2026 20:47