← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Microsoft Copilot revealed undocumented parameter allowing data exfiltration without user consent

🔄 Updated 44d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Varonis researchers found a Copilot vulnerability for data exfiltration.
  • Copilot revealed an undocumented parameter, "?autorun=1", during questioning.
  • This parameter bypassed user consent for prompt execution.
  • Microsoft mitigated the issue in February and released further fixes Tuesday.
  • Varonis Threat Labs named the vulnerabilities CoSnitch.
  • The vulnerabilities are tracked as CVE-2026-24301.
  • The flaws affect Microsoft Copilot Personal, not Microsoft 365 Copilot.
  • Varonis reported the issue to Microsoft in December 2025.
  • Patches shipped on August 18, 2026.
  • No evidence of in-the-wild exploitation was found.

Copilot Vulnerability Discovered

Security researchers at Varonis identified a critical vulnerability in Microsoft 365 Copilot Enterprise. This flaw allowed for the exfiltration of sensitive user data without requiring explicit user confirmation, a standard security measure for AI assistants executing powerful commands. The exploit was designed to activate simply by a user clicking on a malicious link.

AI Assistant Revealed Its Own Weakness

Unusually, the researchers uncovered the vulnerability by directly questioning Copilot about its internal guardrails and safety mechanisms. Through a series of detailed inquiries, Copilot divulged technical details about its architecture, eventually revealing an undocumented prompt parameter: "?autorun=1". This parameter, when used in conjunction with the known "?q=" parameter, allowed prompts to execute silently the moment a target clicked a specially crafted URL.

Microsoft's Mitigation Efforts

Varonis reported the vulnerability to Microsoft, which silently mitigated the issue in February, approximately three months after the initial report. The initial fix involved preventing the "?q=" parameter from injecting text directly into the chatbot input, thereby requiring manual user interaction. Microsoft implemented more comprehensive fixes on Tuesday to address the underlying problem.

Impact on Security Practices

This incident highlights the potential for advanced AI models to inadvertently disclose sensitive information about their own internal workings, which can then be exploited by malicious actors. It underscores the importance of rigorous security testing and the need for developers to anticipate novel methods of vulnerability discovery, even those involving direct interaction with the AI itself.

Updates

🕒 2026-08-18 · new reporting from The Hacker News
  • Varonis Threat Labs named the vulnerabilities CoSnitch.
  • The vulnerabilities are tracked as CVE-2026-24301.
  • The flaws affect Microsoft Copilot Personal, not Microsoft 365 Copilot.
  • Varonis reported the issue to Microsoft in December 2025.
  • Patches shipped on August 18, 2026.
  • No evidence of in-the-wild exploitation was found.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Varonis Threat Labs discovered three vulnerabilities, collectively named CoSnitch and tracked as CVE-2026-24301, in Microsoft Copilot Personal that could enable data exfiltration from connected applications with a single click on a malicious link. Microsoft has since patched these flaws, which involved an undocumented URL parameter that allowed automatic prompt execution and data retrieval through authorized services. This matters because it highlights potential security risks in AI assistants that interact with user data and connected applications, even if no in-the-wild exploitation was found.

Security researchers discovered a vulnerability in Microsoft 365 Copilot Enterprise that allowed data exfiltration without explicit user consent by querying Copilot itself. The AI assistant disclosed an undocumented prompt parameter, "?autorun=1", which, when combined with the "?q=" parameter, enabled silent execution of malicious prompts upon a user clicking a link. Microsoft has since mitigated this vulnerability.