What Happened
Varonis Threat Labs disclosed CVE-2026-24301, a critical vulnerability nicknamed CoSnitch, chaining three separate weaknesses in Microsoft Copilot Personal to exfiltrate data from a victim’s connected accounts after a single click on a malicious link. One of the weaknesses involved an undocumented URL parameter combined with the standard query parameter, causing an attacker-supplied prompt to execute the moment the page loaded, without further interaction from the victim. Varonis found the flaw using a technique it calls meta-hacking, prompting Copilot to explain why a proposed attack would fail and having the assistant reveal its own internal architecture and the exact undocumented parameter needed to carry it out in the process. Microsoft patched the issue on August 18, roughly eight months after Varonis reported it in December 2025, and the company found no evidence of exploitation before the fix shipped. CoSnitch marks the third Copilot vulnerability Varonis has disclosed in 2026, following earlier flaws nicknamed Reprompt and SearchLeak.
Why This Matters for Canadian Organizations
Copilot Personal links to individual Microsoft accounts, including Outlook, OneDrive, and other connected services many Canadians use for both personal and small-business purposes, meaning a successful CoSnitch attack risks reaching email, files, and other personal information without the victim noticing. The eight-month gap between disclosure and patch shows how long a serious flaw in a widely deployed AI assistant sits unresolved, a timeline Canadian privacy regulators and OSFI-regulated institutions increasingly scrutinize when assessing vendor risk from AI-integrated productivity tools. Businesses permitting employees to link personal Copilot accounts to work-adjacent data face a PIPEDA exposure point falling outside standard enterprise Microsoft 365 security controls, since Copilot Personal operates under consumer account settings rather than organizational policy.
What to Do
Individuals and organizations using Copilot Personal should confirm the account reflects Microsoft’s August 18 patch and treat unexpected links referencing Copilot or Microsoft account activity with caution until confirming their legitimacy through official channels. Businesses should review whether employees connect personal AI assistants to accounts holding work-related data and set clear guidance separating personal and organizational account use. Full technical detail on the discovery and exploit chain is available from The Hacker News and Varonis.






