type: cve ยท created: 2026-08-19 ยท updated: 2026-08-19 ยท tags: [cve, microsoft-copilot, data-exfiltration, ai] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, software-development] ยท au_impact: true
CVE-2026-24301 ("CoSnitch")
CVE-2026-24301 is part of a cluster of three vulnerabilities in Microsoft Copilot Personal, disclosed by Varonis Threat Labs and collectively dubbed "CoSnitch". The flaws let a single click on a crafted link silently exfiltrate data from connected apps.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-24301 (core of "CoSnitch") |
| Vendor | Microsoft โ Copilot Personal |
| Researcher | Varonis Threat Labs |
| Impact | One click on crafted link โ silent data exfiltration from connected apps |
| Root cause | Undocumented autorun=1 URL parameter Copilot itself surfaced during testing |
| Fix | Patches shipped 18 August 2026 |
| Source | The Hacker News โ Tier 2/4 |
The flaws turn on an undocumented autorun=1 URL parameter. Microsoft shipped patches on 18 August.