What happened
A crafted URL causes Copilot to run attacker-supplied instructions in the victim's authenticated session and access data exposed through connected applications.
2026-08-18
HighPrimaryAnalysis of CoSnitch, a one-click Microsoft Copilot Personal attack chain that used hidden prompt execution to access and exfiltrate data from connected services.
What happened
A crafted URL causes Copilot to run attacker-supplied instructions in the victim's authenticated session and access data exposed through connected applications.
Why it matters
Demonstrated exposure of sensitive email, calendar, cloud-drive, Copilot history, and persistent-memory data available to the victim's assistant session.
Missing authorization check
Fresh, action-specific authorization before Copilot reads or exports sensitive connected-service data.
Would PP block it?
Even after attacker instructions execute, each protected connector access or export would need an independent receipt binding the user, data scope, and destination. Ungated connectors would remain exposed.
Incident analysis
2025-12-01
Varonis reports the CoSnitch chain to Microsoft during coordinated disclosure.
2026-08-18
Varonis publicly discloses CoSnitch and CVE-2026-24301 after remediation.
Authorization boundary
This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Credential Gate can require a signed receipt for sensitive connector reads and exports, but PP does not prevent the initial browser or prompt-injection vulnerability.
Related incidents and controls
EchoLeak CVE-2025-32711: Zero-Click Prompt Injection in M365 Copilot Silently Exfiltrates Email, Teams, and SharePoint Data Without User Interaction
RovoBlast: One-Click Prompt Injection in Atlassian Rovo Exfiltrates Enterprise Bitbucket, Jira, and Slack Data
App Host Vercel Says It Was Hacked and Customer Data Stolen
Start small
This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.