Cybersecurity
Microsoft patches a one-click Copilot data-theft flaw eight months after disclosure
The bug let a single malicious link pull data from a victim's connected Gmail, Drive and Calendar — and Copilot itself revealed the undocumented parameter that made it work.
Original cover art, generated for this story. THE VISSION does not republish third-party press imagery.
The short version
- Microsoft patched CVE-2026-24301, dubbed CoSnitch, on August 18, roughly eight months after Varonis Threat Labs reported it in December 2025.
- The flaw let one click on a crafted link run an attacker's embedded prompt inside the victim's authenticated Copilot session, reaching connected Gmail, Google Drive, Google Calendar and Copilot chat history.
- It relied on an undocumented autorun URL parameter that Copilot disclosed itself, unprompted, while explaining why auto-execution was supposed to be impossible.
- Microsoft says it found no evidence the flaw was exploited before the patch shipped; it is the third Copilot vulnerability Varonis has disclosed this year.
The bug let a single malicious link pull data from a victim's connected Gmail, Drive and Calendar — and Copilot itself revealed the undocumented parameter that made it work.