Researchers at Varonis Threat Labs have identified three critical vulnerabilities in Microsoft Copilot Personal, dubbed 'CoSnitch,' which could allow attackers to silently steal data from connected applications.

  • Varonis Threat Labs discovered three vulnerabilities named 'CoSnitch' in Microsoft Copilot Personal.
  • A single click on a malicious link can trigger data exfiltration from connected apps.
  • The flaw exploits an undocumented URL parameter surfaced by the AI assistant itself.

In a significant blow to AI security, Varonis Threat Labs has disclosed a set of vulnerabilities within Microsoft Copilot Personal. These flaws, collectively referred to by researchers as 'CoSnitch', present a high-risk scenario where a user could inadvertently compromise their entire digital ecosystem through a single, malicious interaction.

The vulnerability allows an attacker to craft a specific URL that, when clicked, silently extracts sensitive information from the victim's connected applications and any data currently active in the Copilot session. What makes this particularly alarming is that the exploit leverages an undocumented URL parameter that was inadvertently surfaced by the AI assistant itself, creating a direct pathway for unauthorized data access.

Why This Matters

BozokMedia analysis shows that as AI assistants transition from simple chatbots to deeply integrated personal agents with access to emails, files, and calendars, the blast radius of a single vulnerability expands exponentially. The CoSnitch exploit demonstrates that the integration layer between AI and third-party apps is currently a primary target for sophisticated cyberattacks.

The seamless integration of AI with personal data creates a massive attack surface that traditional security perimeters are often unequipped to defend.

Historically, security researchers have warned about the risks of 'AI hallucinations' and 'prompt injection.' However, CoSnitch represents a more structural failure in how session data and URL parameters are handled during AI-driven interactions, highlighting a need for more rigorous sandboxing of AI-driven web requests.

Frequently Asked Questions

1. How does the CoSnitch exploit work?
It uses a crafted link to exploit an undocumented URL parameter, allowing data to be pulled from connected apps without user knowledge.

2. Is my Microsoft account compromised?
While the flaw exists, users should remain vigilant against clicking suspicious links and ensure robust security settings are enabled.

Did You Know?: Many AI vulnerabilities arise not from the AI's logic, but from the underlying web protocols used to communicate with external apps.