CoSnitch: Three Copilot Flaws Enable One-Click Data Theft
Varonis Threat Labs found three flaws in Microsoft Copilot Personal, named CoSnitch, that let attackers silently pull data from all connected apps in one click.

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal today, collectively named CoSnitch, that allow an attacker to silently exfiltrate data from every app connected to a victim’s Copilot session — triggered by a single click on a malicious link.
The flaws hinge on an undocumented URL parameter that Copilot itself surfaced during research. By crafting a link that exploits this parameter, an attacker can instruct Copilot to query and return data from any connected application — email, calendar, files, and linked SaaS tools — without the user’s knowledge.
A related finding reported by Dark Reading describes a “meta-hacking” technique: using Copilot’s own capabilities to map out its internal architecture and security weaknesses. Researchers prompted the assistant into documenting its own system, surfacing reconnaissance information that would otherwise require significant external effort to obtain.
No CVE identifiers have been assigned yet. Varonis coordinated disclosure with Microsoft; as of this publication, no patch announcement has been made.
What to do now
High priority — shrink your Copilot Personal attack surface:
1. Audit connected app integrations. In Copilot Personal settings, remove every integration you don’t actively use. Each connected app expands what an attacker can reach if they trigger CoSnitch. Email and calendar integrations are the highest-value targets; review those first.
2. Don’t click links in Copilot-generated output from untrusted or forwarded sessions. The exfiltration path requires a user click on a crafted link. Treat Copilot-generated links with the same skepticism as any unsolicited URL.
3. Check OAuth scope on Copilot integrations. If your organization manages Copilot access via Microsoft Entra or Conditional Access, confirm that OAuth tokens issued to Copilot are scoped to what your users actually need — not blanket read access across every connected service.
Lower priority, but track:
4. Monitor for unusual Copilot API activity. Rapid, structured, non-interactive query patterns through an active Copilot session may indicate automated data extraction. Log aggregation that captures Microsoft Graph API calls would surface this.
5. Watch for Varonis’s full technical writeup. Complete technical details are expected to follow standard responsible disclosure timelines. When they publish, verify whether your organization’s Copilot Personal configurations match the vulnerable patterns.
Watch Microsoft’s Security Response Center for patch timing; there is no workaround beyond reducing connected-app scope in the interim.
This is the third Copilot-related security disclosure in recent months. A prompt injection technique published in July showed Copilot could falsify document figures and embed the attack payload into its own output files, re-triggering on the next session. Before that, researchers found Copilot’s backend models would produce outputs via workflow paths that chat interfaces blocked. CoSnitch adds a third vector: an attacker who gets a user to click one link gets read access to everything Copilot is connected to.
The pattern is consistent: Copilot’s deep integration with productivity tools makes it a high-value pivot point for ambient-authority attacks. Each new disclosure expands the connected-app footprint from a convenience feature into an attack surface. Security teams that haven’t scoped down Copilot Personal permissions have a practical reason to do it now.
Sources: Varonis Threat Labs, via The Hacker News; Dark Reading.
Found this useful? Share it.


