CVE-2026-24301 affected Microsoft Copilot Personal; Microsoft 365 Copilot Enterprise was unaffected. The flaw could enable one-click execution of an attacker-controlled prompt inside an authenticated session.
CoSnitch combined the q parameter with the undocumented autorun=1 parameter, causing an attacker-supplied prompt to execute automatically without another user gesture.
The prompt could query already-authorized connected services and use Copilot’s built-in URL-fetch capability for AI assistant data exfiltration.
Microsoft patched the issue on August 18, 2026. Organizations should review AI connectors, permissions, managed-device access, and endpoint investigation processes.
CVE-2026-24301 shows how a single crafted link could turn an authenticated Microsoft Copilot Personal session into a potential data-exfiltration path.
Varonis Threat Labs disclosed three vulnerabilities collectively named CoSnitch. The attack combined automatic prompt execution with Copilot’s existing access to connected services and its ability to fetch URLs. An attacker could potentially retrieve information already available to the assistant and send it to an external server without gaining additional permissions.
Microsoft shipped patches on August 18, 2026, and Varonis reported no evidence of exploitation in the wild. Still, the incident raises a broader AI security question for enterprises: what happens when an assistant can act on data that users have already authorized it to access?
CoSnitch turned a trusted Copilot session against its user
CVE-2026-24301 did not rely on stolen credentials or newly granted permissions. Instead, CoSnitch operated inside an already authenticated Copilot Personal session and used capabilities available to that user.
The attack depended on two URL parameters:
q: Pre-filled the Copilot input field with the attacker-controlled prompt.
autorun=1: An undocumented parameter that caused the prompt to execute automatically. Varonis discovered autorun=1 while analyzing Copilot’s Share functionality, which used the parameter to automatically execute shared prompts.
Both together: Allowed the prompt to run on page load without another user gesture.
Varonis found that q alone only populated the input box. Automatic execution required both parameters. Once execution began, the prompt could run to completion even if the victim immediately closed the Copilot tab.
This makes the prompt injection path particularly important for defenders. The malicious instruction did not require malware, credential theft, or a newly authorized integration. The victim only needed to click the crafted link while signed in to Copilot Personal.
The resulting activity ran within the user’s existing session and inherited the same capabilities available to instructions the user entered directly.
CVE-2026-24301 did not grant Copilot new permissions. Instead, the attack operated within the access already available to the authenticated user.
Varonis reported that the injected prompt could retrieve information from connected services, including:
Email content and metadata
Calendar details
Google Drive file information
Previous Copilot conversations
Stored memory instructions
The prompt could encode the retrieved data into a URL and instruct Copilot to fetch that attacker-controlled URL, carrying the encoded information to the attacker’s server.
For defenders, the lesson is clear: AI assistant data exfiltration can turn existing authorization into a risk when attacker-controlled instructions influence what the assistant accesses and sends.
CVE-2026-24301 exposes an AI authorization problem
CVE-2026-24301 highlights a challenge for SaaS security: valid authentication does not always mean the resulting action reflects the user’s intent.
CoSnitch operated within the victim’s existing Copilot Personal permissions. For enterprise identity security, that makes AI connectors an important authorization boundary.
Security teams should:
Inventory connected AI applications.
Remove unnecessary permissions and connectors.
Apply least privilege to connected services.
Review what sensitive data assistants can access.
The scope also matters. Varonis investigated Copilot Personal; the published research does not establish that CoSnitch affected Microsoft 365 Copilot.
Memory poisoning can outlive the original interaction
CoSnitch also exposed a separate persistent-memory risk. Varonis found that a crafted webpage, when summarized by Copilot, could place attacker-controlled instructions into the assistant’s memory.
Those instructions could then influence later Copilot sessions until removed.
For AI security investigations, teams should therefore consider more than the immediate conversation:
Stored memory and instructions
Connected applications
Previous assistant activity
Persistent AI state can extend the impact of malicious instructions beyond the interaction that introduced them.
What should security teams review after CoSnitch?
Microsoft patched CVE-2026-24301, and Varonis found no evidence of exploitation in the wild. The broader lesson is to reduce unnecessary AI access before another flaw can abuse it.
Security teams should:
Review connectors: Remove unnecessary AI integrations.
Minimize permissions: Limit connected services to required data.
Govern personal AI use: Define how consumer AI tools can access corporate information.
Inspect persistent state: Include AI memory and stored instructions in investigations.
Correlate endpoint evidence: Review browser and endpoint activity when an AI event forms part of a wider incident.
These controls reduce the potential scope of AI assistant data exfiltration without treating legitimate AI activity as inherently malicious.
Featured resource
Introduction to Hexnode XDR
Hexnode XDR unifies threat visibility, investigation, correlation, and remediation to strengthen enterprise endpoint security operations.
It cannot stop SaaS-side prompt execution, but if compromised data contributes to a secondary attack on a managed endpoint, Hexnode XDR can support containment by isolating the affected device.
Hexnode does not replace Copilot-specific monitoring, SaaS security, identity investigation, or Microsoft’s remediation for CVE-2026-24301.
FAQs
What is CVE-2026-24301?
CVE-2026-24301 tracks CoSnitch, a security issue affecting Microsoft Copilot Personal. Varonis demonstrated automatic prompt execution, connected-service data exfiltration, and persistent memory poisoning.
Did CoSnitch affect Microsoft 365 Copilot?
Published CoSnitch research identifies Copilot Personal as the affected product. It does not establish that the same vulnerability affected Microsoft 365 Copilot.
Was CVE-2026-24301 exploited in the wild?
Varonis reported no evidence of CoSnitch exploitation in the wild. Microsoft shipped patches on August 18, 2026.
CoSnitch makes AI permissions part of the security perimeter
CVE-2026-24301 shows why enterprises should treat AI assistant permissions as part of their broader AI security model. When assistants connect to email, files, calendars, and other services, those permissions expand what an attacker may reach if the assistant’s behavior is manipulated.
Microsoft has patched CoSnitch, and Varonis found no evidence of exploitation in the wild. Organizations should still minimize AI permissions, govern connectors, restrict sensitive access, and maintain strong endpoint and identity controls.
Strengthen security across managed endpoints
Manage device compliance and respond to endpoint threats with Hexnode.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.