AI

Microsoft patched Copilot’s one-click flaw. The poisoned memories may still be sitting there.

Varonis Threat Labs disclosed CoSnitch — CVE-2026-24301 — on 18 August, the same day Microsoft’s fix shipped, roughly eight months after the December 2025 report. The exfiltration path is closed. Instructions written into Copilot’s memory store before the patch survive password changes, session revocation and device re-enrolment.

N Noah · The Sharp Brief · August 22, 2026 · 4 min read

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal this week, collectively named CoSnitch and tracked in Microsoft’s Security Update Guide as CVE-2026-24301. A single click on a crafted link could make the assistant run an attacker’s prompt inside the victim’s authenticated session, query the services that user had already connected, and quietly ship the results to a server the attacker controlled.

Microsoft shipped the fix on 18 August 2026. Varonis says it reported the issue in December 2025 — roughly eight months. Microsoft has said the flaw affected only Copilot Personal, the consumer assistant at copilot.microsoft.com, with no customer action required because the fix is already deployed. The researchers found no evidence of exploitation in the wild.

The way they found it is the part worth sitting with. They repeatedly asked Copilot why a prompt could not be made to run without a user gesture. Each refusal came wrapped in a technical justification, and the assistant eventually volunteered the name of an undocumented URL parameter, autorun=1, plus the session conditions under which it worked. The researchers built the URL exactly as described. It fired. Varonis’ own summary: Copilot “wasn’t breached; it was played.”

Our take: The exfiltration path is patched. The memory problem is a different shape. Varonis says instructions written into Copilot’s memory store survive password changes, session revocation and device re-enrolment, and stay active until the user deletes them from memory settings — and its disclosure does not state whether Microsoft’s remediation retroactively removed entries created before 18 August. A patched door does not empty the room behind it.

What the three flaws actually did

Varonis grouped the findings into three parts. Two chain together into the one-click path; the third is separate.

Varonis notes the outbound request is indistinguishable at the network layer from the fetches Copilot makes when summarising an ordinary page. The memory write produces no process, no file, no network connection and no log entry that security tooling would flag. It is visible in exactly one place: Copilot’s memory interface.

Not an isolated finding

Researchers Håkon Måløy and Johann Rehberger have both reported Copilot memory manipulation this year, Rehberger’s work associated with CVE-2026-24299. Microsoft set out its position on the attack class in a 22 June security post — scoped to Microsoft 365, not the consumer product. There, it says memories pass sanitisation and prompt-injection checks on write, that Task Adherence checks run on every explicit memory write, and that updates land in organisational audit logs surfaced through a MemoryUpdated field in Defender and Sentinel. No equivalent audit trail is described for the consumer assistant.

What to watch

The five-minute version for your own account

Varonis’ advice is unglamorous and correct: open your assistant’s connected-apps list and disconnect anything you are not actively using; open the memory settings and read every entry, deleting anything you do not remember creating; and treat a link that opens an AI assistant with the same suspicion you would give a link that opens a login page. The assistant holds your permissions. Anything that can steer it is standing exactly where you stand.

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.