Loading article…
Microsoft has patched the critical CoSnitch vulnerability in Copilot after an 8-month delay. The flaw allowed data exfiltration and persistent memory hacks.
Microsoft has issued a patch for a critical security vulnerability in its personal Copilot AI assistant, closing a security hole that allowed attackers to silently exfiltrate data and poison the AI’s persistent memory [1, 2]. The vulnerability, designated CVE-2026-24301, remained unpatched for more than eight months after its initial disclosure by security firm Varonis on December 31, 2025 [1, 2].
| At a glance | |
|---|---|
| Product | Microsoft Copilot (Personal) |
| Vulnerability | CoSnitch (CVE-2026-24301) |
| Disclosure Date | December 31, 2025 |
| Patch Status | Fully remediated |
The CoSnitch flaw functioned by chaining three distinct weaknesses into a single attack vector, exploiting the inability of large language models to differentiate between user data and executable instructions [1, 2]. First, an undocumented URL parameter allowed attackers to trigger prompts automatically upon page load without user interaction [1]. Second, the AI could be forced to query connected applications—such as Gmail, Drive, or OneDrive—and exfiltrate the results to external servers [1, 2].
The most significant component, according to security researchers, was the persistent memory poisoning [1]. By summarizing a crafted webpage, an attacker could inject instructions into the user’s permanent memory store, which remained active even after password changes, session revocations, or device re-enrollments [1, 2]. Varonis researchers discovered the vulnerability by using the AI against itself, reframing refusals into follow-up questions until the system mapped its own internal architecture and undocumented parameters [1, 2].
While Microsoft stated that enterprise customers using Microsoft 365 Copilot are not affected, industry analysts warn that the distinction is porous [1]. Because many enterprise environments include personal Copilot accounts used by staff, the vulnerability in the consumer version poses a potential risk to corporate networks [1]. This concern is heightened by Microsoft’s ongoing efforts to unify its AI offerings under a "Copilot Fusion" architecture, which could eventually merge these distinct security profiles [1].
The delay in patching has drawn criticism regarding the tension between rapid AI deployment and security [2]. Although Microsoft issued a partial fix on February 1, 2026, that reduced the risk, the full remediation was not completed until this week [1, 2]. Some consultants argue that because the exploit relies on the same features marketed as Copilot’s core value—such as the ability to summarize web content and access connected apps—these vulnerabilities may be subject to perpetual mitigation rather than permanent elimination [1].
The CoSnitch incident highlights a fundamental challenge for AI developers: when the product's primary utility is its ability to act on data, the distinction between a helpful feature and an exfiltration tool becomes a matter of intent rather than function [1].
Coverage is mostly measured — 206 of 206 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 21, 2026 · How we report
Microsoft was founded on April 4, 1975, by Bill Gates and Paul Allen.
The U.S. Department of Justice and 20 states accused Microsoft of illegally maintaining an operating system monopoly by bundling Internet Explorer with Windows.
Microsoft leadership directed engineers to quickly test and deploy the DeepSeek R1 model on Azure AI Foundry and GitHub.