Three Copilot Personal Flaws ("CoSnitch") Could Let a Single Click Exfiltrate Connected-App Data
What happened
Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively dubbed CoSnitch. According to the researchers, the flaws could let an attacker craft a malicious link that, with a single click by the victim, silently exfiltrates data from apps connected to the victim's Copilot session and other information available to that session. The report indicates the issue turns in part on an undocumented URL parameter that the assistant itself surfaces. As of this writing, patch status and full technical details beyond this summary have not been confirmed.
Why it matters for defenders
AI assistants like Copilot Personal are increasingly wired into a user's broader app ecosystem, which means a flaw in the assistant's session or link-handling logic can effectively become a pivot point into everything it's connected to. A one-click exfiltration path is attractive to attackers because it lowers the bar for compromise dramatically — no malware, no credential theft, just a link a user is convinced to open. Any organization or individual with Copilot Personal connected to other applications should treat this as a potential exposure until Microsoft's response and remediation are clarified.
What defenders should watch for now
- Track official guidance from Microsoft on CoSnitch and Copilot Personal patch status, and apply updates promptly once available.
- Review which third-party apps and data sources are connected to Copilot sessions, and reduce connected-app scope where not strictly needed.
- Educate users on the risk of clicking unsolicited or unexpected links tied to AI-assistant sessions, similar to phishing awareness training.
- Where telemetry exists, monitor for anomalous Copilot session activity — unusual outbound requests, unexpected data access patterns, or session parameters that deviate from normal usage — as a general hunting angle rather than a specific signature.
- Watch for follow-up technical writeups from Varonis or Microsoft that may detail the specific URL parameter and exploitation mechanics, which would enable more targeted detections.
Developing story
This is net-new intelligence based on a single vendor disclosure, and further technical and remediation details are expected as Microsoft and Varonis provide more information. For the original report, see The Hacker News.