Varonis Threat Labs disclosed three chained vulnerabilities in Microsoft Copilot Personal, collectively dubbed CoSnitch and tracked as CVE-2026-24301, that could let attackers exfiltrate data from a victim’s connected accounts via a single malicious link click. The flaws stemmed from an undocumented URL parameter that triggered automatic prompt execution within an authenticated session, potentially exposing email, calendar, and cloud storage data. Microsoft released server-side patches on August 18, 2026, and researchers found no evidence the flaws were exploited before the fix.
