Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-18

HighPrimary

CoSnitch One-Click Chain Makes Microsoft Copilot Personal Execute Hidden Instructions and Exfiltrate Connected Data

Analysis of CoSnitch, a one-click Microsoft Copilot Personal attack chain that used hidden prompt execution to access and exfiltrate data from connected services.

Microsoft Copilot PersonalCredential exposureOne-click prompt execution and connected-service data exfiltrationAuthenticated Microsoft Copilot Personal session and connected applications

What happened

A crafted URL causes Copilot to run attacker-supplied instructions in the victim's authenticated session and access data exposed through connected applications.

Why it matters

Demonstrated exposure of sensitive email, calendar, cloud-drive, Copilot history, and persistent-memory data available to the victim's assistant session.

Missing authorization check

Fresh, action-specific authorization before Copilot reads or exports sensitive connected-service data.

Would PP block it?

Even after attacker instructions execute, each protected connector access or export would need an independent receipt binding the user, data scope, and destination. Ungated connectors would remain exposed.

Incident analysis

Timeline and technical read

Timeline

  1. 2025-12-01

    Varonis reports the CoSnitch chain to Microsoft during coordinated disclosure.

  2. 2026-08-18

    Varonis publicly discloses CoSnitch and CVE-2026-24301 after remediation.

Technical breakdown

  • Researchers induced Copilot to reveal details about an undocumented prompt-execution parameter.
  • A crafted link supplied attacker-controlled instructions to an authenticated Copilot Personal session.
  • The chain used Copilot's existing access to connected services to retrieve sensitive information.
  • Exfiltration techniques moved retrieved data outside the intended assistant workflow.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Copilot connector boundary and data-export action router
Still needs
Browser-link handling and prompt-injection prevention remain platform responsibilities.
Receipt required for
Reading sensitive connected data and exporting it to an external destination

A Credential Gate can require a signed receipt for sensitive connector reads and exports, but PP does not prevent the initial browser or prompt-injection vulnerability.

Start small

Put the relevant gate at this action boundary.

This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop