CoSnitch flaws let Copilot execute prompts and exfiltrate
🛡️ Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to run prompts and pull data from connected apps within a victim's authenticated session. The issues — collectively named CoSnitch and tracked as CVE-2026-24301 — rely on an undocumented URL parameter pairing (autorun=1 and q) to trigger automatic prompt execution and data exfiltration. Microsoft received the report in December 2025 and shipped patches on August 18, 2026.
