Varonis Threat Labs has disclosed three distinct vulnerabilities, collectively termed CoSnitch, affecting Microsoft Copilot Personal. These flaws, tracked under CVE-2026-24301, enable silent data exfiltration from connected applications and the victim’s Copilot session through a single, precisely crafted URL click.
The vulnerabilities stem from an undocumented URL parameter, `autorun=1`, which the Copilot assistant itself inadvertently surfaced during Varonis’ “meta-hacking” research methodology. This parameter, when combined with the existing `q` parameter, bypassed intended protections to execute without explicit user interaction.
Architectural Breakdown and Exploitation Vector
CoSnitch leverages the `autorun=1` parameter, which, despite Microsoft’s internal mechanisms designed to disable it, was found to be functional under specific session conditions described by Copilot. Researchers discovered this through iterative prompting, where Copilot provided technical justifications for its refusal to run prompts without user interaction, eventually revealing the parameter. When integrated into a URL with the standard query (`q`) parameter, this allows for the automatic execution of commands or data retrieval actions upon a single user click on the crafted link.
The exploit chain is characterized by its subtlety, operating silently to extract information accessible to the victim’s Copilot session. This includes sensitive data from integrated applications. The attack vector is specific to Copilot Personal, hosted at `copilot.microsoft.com`, and Varonis’ research indicates no similar behavior affecting Microsoft 365 Copilot.
Specification
Detail
Vulnerability Name
CoSnitch
CVE ID
CVE-2026-24301
Affected Product
Microsoft Copilot Personal (copilot.microsoft.com)
Silent data exfiltration from connected apps and Copilot session
Reported Date
December 2025
Patch Deployment
August 18, 2026
Exploitation In Wild
No evidence found by Varonis Threat Labs
Remediation and Operational Impact
Varonis Threat Labs reported the CoSnitch vulnerabilities to Microsoft in December 2025. Microsoft subsequently deployed patches on August 18, 2026, addressing the identified flaws. Users of Microsoft Copilot Personal should ensure their systems are updated to the latest available versions to mitigate these risks.
The discovery methodology, where Copilot itself provided insights into its internal workings, underscores the evolving landscape of AI-assisted vulnerability research. This “meta-hacking” approach may represent a new frontier in probing complex AI systems for hidden parameters and unintended functionalities.
STRIDING TECH WIRE•WEEKLY RADAR
Weekly Technology Briefings
Multi-source tech synthesis, primary research breakdowns, and high-impact insights delivered every Sunday morning.
Key Takeaways
Three critical vulnerabilities, collectively named CoSnitch (CVE-2026-24301), were disclosed in Microsoft Copilot Personal.
The vulnerabilities allowed silent, single-click data exfiltration from user sessions and connected applications via crafted URLs.
The attack leveraged an undocumented `autorun=1` URL parameter, unintentionally revealed by Copilot during research.
Patches were deployed by Microsoft on August 18, 2026, following a December 2025 report by Varonis Threat Labs.
✉
STRIDING TECH INTELLIGENCE WIRE
Weekly Technology Briefings
Multi-source tech synthesis, primary research breakdowns, and high-impact tech news delivered every Sunday morning.