CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4616

As cited

Copy frozen at (site build).

vulnerabilities

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could enable attackers to exfiltrate data from connected applications through a single malicious link click. The flaws, collectively termed CoSnitch, exploit an undocumented URL parameter accessible to the assistant.

Why it matters: Organizations and users of Microsoft Copilot Personal with connected third-party applications face unauthorized data extraction risk; patching or disabling the affected URL parameter should be prioritized.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could enable attackers to exfiltrate data from connected applications through a single malicious link click. The flaws, collectively termed CoSnitch, exploit an undocumented URL parameter accessible to the assistant.

Why it matters: Organizations and users of Microsoft Copilot Personal with connected third-party applications face unauthorized data extraction risk; patching or disabling the affected URL parameter should be prioritized.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary