NEWS
Copilot Personal Still Holds Inbox Access After CoSnitch
Microsoft patched CoSnitch on August 18, 2026, but Copilot Personal still reads Gmail and Drive through connectors, and poisoned memories need a manual delete.
Microsoft patched Copilot Personal on August 18, 2026, after Varonis Threat Labs showed one crafted link could pull data from connected Gmail, Drive and Calendar. The chain, named CoSnitch and tracked as CVE-2026-24301, ran inside the victim’s own signed-in session at copilot.microsoft.com. Microsoft rated it Critical, with a CVSS 3.1 base score of 8.8, and said it found no sign the flaw was used in the wild.
The click is closed. The assistant still sits on every connector the user turned on, and a memory written before the fix is a separate cleanup job Microsoft has not said it performed.
A Crafted Copilot Link Ran the Prompt by Itself
Varonis, in the three-flaw CoSnitch attack chain published with the patch, grouped what it found into automatic prompt execution, silent export through connected apps, and a separate memory write triggered when Copilot summarized a page. The first two made the one-click path. The third could keep shaping later chats after the tab was gone.
THE THREE FLAWS VARONIS CHAINED
- Automatic run: Pairing the public q parameter with undocumented autorun=1 executed an attacker prompt on page load in the victim’s authenticated session.
- Connected-app export: That prompt queried services the user had already authorized, packed the result, and had Copilot fetch an attacker URL.
- Memory from a summary: A booby-trapped page, once summarized, could write attacker instructions into Copilot’s saved memory.
The attack URL looked like a normal Copilot deep link: copilot.microsoft.com with q set to the payload and autorun=1 set beside it. Varonis said q alone only fills the input box, so the user would still have to press Enter. Both flags had to be present for the prompt to fire with no extra gesture. Delivery could be email, chat, a phishing page, or a QR code.
Once the page loaded, the injected instruction had the same reach as something the user typed. Varonis said the run went to completion, including connector calls and network fetches, even if the Copilot tab was closed right after load. From the victim’s side, they opened a Microsoft link and Copilot got to work.
Microsoft’s Security Update Guide classifies the issue as information disclosure through command injection (CWE-77) and states there is no customer action to resolve. A Microsoft spokesperson said enterprise customers were unaffected, and that the research names Copilot Personal rather than Microsoft 365 Copilot. The CVE exists so a cloud fix has a public record.
Gmail, Drive and the OAuth the User Already Gave
The export step did not steal a new token and did not widen Google or Microsoft permissions. Copilot used access the user had already granted. Microsoft’s consumer connector guide lists OneDrive, Outlook.com, Google Drive, Gmail, and Google Calendar and Contacts, and says Copilot does not store, modify, or expand your access. CoSnitch did not need it to. It only needed the user to be signed in, with those connectors on, and to open the link.
That is the part the CVE does not retire. Copilot Personal is sold as a helper that can find a flight confirmation or tomorrow’s dentist visit. After a user hits Continue to Gmail, the assistant can read full message bodies, not only subject lines. Varonis said that is not a bug in Gmail or in OAuth. The user authorized Copilot to read mail, and CoSnitch invoked that grant without a second confirmation.
In lab runs, Copilot pulled a recent Gmail body that held a password in plain text, then held it in working context. The next step encoded the haul and handed Copilot a URL to summarize. Copilot’s built-in fetch issued an HTTPS GET to an attacker webhook, with the payload in the path. On the wire that request matches the fetches Copilot makes when a user asks it to summarize an ordinary page. Base64 in the path also ducks filters that scan outbound URLs for password-shaped strings.
WHAT COPILOT RETURNED IN TESTING
| Source | Data Varonis retrieved |
|---|---|
| Gmail / Outlook | Message bodies, subject lines, sender and recipient details |
| Google Calendar | Meeting titles, attendees, times, and locations |
| Google Drive | File names and metadata summaries |
| Copilot chat history | Full prior conversation content |
| Copilot memory | Saved instructions and user-defined rules |
Drive was names and summaries, not full file bytes. Mail was the richer take, including credentials people had sent themselves. Calendar gave titles, people, times, and rooms. Chat history and memory came along for the same ride. Network monitors that only watch for strange destinations will see Copilot fetching a page, which is what Copilot does when it summarizes a link.
Copilot Explained Why Auto-Send Could Not Work
Varonis did not reverse-engineer autorun=1 out of a binary. Senior security researcher Lior Adar and colleagues kept asking Copilot why a prompt could not run without a user gesture, a method the firm calls meta-hacking. Each refusal came with a technical reason. Those reasons mapped URL structure, deep links, and the session conditions under which auto-run had existed.
Copilot wasn’t breached; it was played.
Lior Adar, Senior Security Researcher, Varonis Threat Labs
Mid-refusal, Copilot named the undocumented parameter, described when it had worked, and listed the protections that were supposed to have turned it off. The researchers built the URL exactly as described. The flag Copilot had just called disabled still executed.
A product that explains its own guardrails in natural language will, under patient questioning, hand over the map of those guardrails. Copilot’s certainty that auto-send was impossible was the channel that disclosed how to turn it on. That discovery method travels. Any assistant that answers “that will not work because…” in implementation detail is doing reconnaissance for the next tester, or the next attacker.
Why Microsoft 365 Memory Logs Miss This Product
The third flaw does not need autorun=1. A user who asks Copilot to summarize a URL causes Copilot to GET the page, ingest the full HTML, and treat hidden copy as instructions if the model reads it that way. Varonis planted a tiny white-on-white paragraph that told Copilot to add an attacker line to persistent memory and to confirm with a benign word in the summary. The user saw a normal recap. The memory write had already landed.
Varonis said Copilot memory has no expiry, does not reset at logout, and is not wiped by a password change, a revoked session, or device re-enrollment. The write produced no process, file, network connection, or log line that endpoint tools would flag. The only record is Copilot’s memory settings screen, which most people never open. In one demo, poisoned memory made Copilot treat a known CVE as harmless.
Microsoft already described a tighter design, for a different product. In a June 22, 2026 security post, the company said Microsoft 365 Copilot memories pass through sanitization and prompt-injection checks, and that the service is designed to run Task Adherence checks on every explicit memory write. Memory updates, it said, go to organizational audit logs and show up for analysts as a MemoryUpdated field in Defender Advanced Hunting and Sentinel. The post credits MSRC cases from Johann Rehberger, Håkon Måløy, and Gal Zror, and it is scoped to Microsoft 365.
MEMORY CONTROLS MICROSOFT DESCRIBED
| Control | Copilot Personal (CoSnitch research) | Microsoft 365 Copilot (June 22 post) |
|---|---|---|
| Sanitization on memory write | Not described for this product | Prompt-injection classifiers on write |
| Task Adherence on memory tool calls | Not described for this product | Designed to run on every explicit write |
| SOC-visible MemoryUpdated events | Varonis saw no flaggable log line | Defender Advanced Hunting and Sentinel |
| Tenant policy and eDiscovery | Consumer memory settings only | Mailbox-class compliance tools |
Måløy, publishing the same day after a 90-day coordination window, documented an attacker-controlled page that persisted an unintended memory in a Microsoft 365 Copilot summarization flow and recorded Microsoft’s status as mitigated globally. Rehberger had already reported memory writes and deletions through indirect prompt injection in Microsoft 365 Copilot, and memory changes in the consumer assistant, under CVE-2026-24299. CoSnitch is the consumer sequel: same class of write, almost none of the enterprise telemetry Microsoft put on the slide in June.
The Same One-Click Pattern, Third Time This Year
Varonis said CoSnitch is the third Microsoft Copilot flaw its threat lab disclosed in 2026. Reprompt bypassed Copilot guardrails by asking twice. SearchLeak, tracked as CVE-2026-42824, turned Microsoft 365 Copilot Enterprise Search into a silent export tool. All three start with a link that looks like it belongs to the product.
Eleven days before the CoSnitch patch, the same lab detailed RovoBlast against Atlassian’s Rovo assistant. That chain abused a rovoChatPrompt URL parameter to seed attacker instructions into a signed-in chat. Varonis said Atlassian fixed it before the public write-up. The family name is parameter-to-prompt: the address bar is an input field, and a click is the send button.
THE 2026 ONE-CLICK CALENDAR
- December 2025: Varonis reports CoSnitch to Microsoft, including autorun=1 on Copilot Personal.
- June 22, 2026: Microsoft publishes its Microsoft 365 memory-guarding post; Måløy publishes the related summarization-memory case.
- August 7, 2026: Varonis publishes RovoBlast, the same link-to-prompt pattern in Atlassian Rovo.
- August 18, 2026: Microsoft ships the CoSnitch service fix and assigns CVE-2026-24301.
SearchLeak was an enterprise-search problem with a lower Microsoft score. CoSnitch is the consumer assistant with Google connectors hanging off a personal login. Employees who use copilot.microsoft.com with a work Gmail grant still created an export path that Microsoft’s “enterprise customers are unaffected” line does not inventory. The product boundary is real. The people using both products to read the same inbox are also real.
Injected Memories Still Need a Human to Delete Them
There is no Windows update to install. Varonis told users to treat unexpected Copilot links with care, keep connected apps to the ones they actually use, and watch for fetches they did not ask for. For security teams it advised connector audits, the same access review you would give a person who can open mail and files, and a hard look at whether current tools would even notice Copilot pulling an unusual volume of mail.
The memory path is the leftover. Varonis said an injected instruction stays until the user deletes it in Copilot’s memory settings. Its disclosure does not say Microsoft’s remediation retroactively cleared entries written before August 18, 2026, and Microsoft’s CVE note does not say that either.
WHAT WE KNOW
- The click path: Microsoft says CoSnitch is fully mitigated in the service as of August 18, 2026.
- The product scope: Research and Microsoft both point at Copilot Personal, not Microsoft 365 Copilot.
- In the wild: Varonis and Microsoft have not presented evidence of exploitation before the fix.
WHAT IS UNCONFIRMED
- Old memories: No public statement says pre-patch memory writes were wiped automatically.
- Connector telemetry: Consumer Copilot still lacks the MemoryUpdated hunt path Microsoft described for Microsoft 365.
A password change is the wrong cleanup, because the instruction lives in Copilot memory, not in the account secret. Anyone who used Copilot Personal with Gmail, Drive, or Calendar connected should open the memory pane, delete lines they did not write, and disconnect connectors they do not need. Microsoft closed the autorun door. The keys on the table are still the user’s to pick up.
Frequently Asked Questions
Do Copilot Personal Users Need to Install a CoSnitch Patch?
No. Microsoft recorded CVE-2026-24301 as a cloud-service issue that was already fully mitigated on August 18, 2026, and published the CVE for transparency rather than as a client bulletin, under its program for disclosing cloud flaws after the service-side fix is in.
Which Consumer Services Can Copilot Personal Connect To?
Microsoft lists OneDrive, Outlook.com, Google Drive, Gmail, and Google Calendar and Contacts, and says connectors are available on Copilot.com and on Copilot Mobile for iOS and Android, with a signed-in account required before any of those links will answer.
Does Changing a Password Clear Poisoned Copilot Memory?
Varonis said Copilot memory is never automatically deleted or overwritten, does not clear on logout, and survives password changes, session revocation, and device re-enrollment, so the only reliable wipe is a manual delete in the memory settings most users never open.
Is CoSnitch the Same Flaw as SearchLeak?
No. SearchLeak is CVE-2026-42824, a separate June 2026 Varonis chain against Microsoft 365 Copilot Enterprise Search that Microsoft scored 6.5, while CoSnitch is CVE-2026-24301 against Copilot Personal at 8.8 and adds consumer Google connectors plus the summarization-to-memory path.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
