< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-18T23:17:22+05:30

Microsoft Copilot Vulnerabilities Enable Single-Click Data Exfiltration via Crafted Links

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, named CoSnitch, enabling single-click data exfiltration via crafted URLs using undocumented parameters. The flaws allow attackers to exploit connected apps and memory stores without expanding user permissions, with patches released in August 2026.

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session.

The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Read original article

*** END OF TRANSMISSION ***