Researchers disclosed a chain of vulnerabilities in Microsoft Copilot Personal, dubbed CoSnitch, that let an attacker-crafted link run prompts inside a victim’s authenticated Copilot session with a single click, silently accessing linked accounts and exfiltrating data from connected Gmail, Drive, and Calendar. A related flaw let attackers plant hidden instructions on a webpage that Copilot would treat as commands when asked to summarize it, poisoning the user’s persistent memory in a way that survived password changes and session revocations. Microsoft patched the vulnerability, tracked as CVE-2026-24301, on August 18, 2026, and researchers found no evidence it was exploited in the wild.