Microsoft Addresses Long-Standing Copilot Vulnerability, Affecting AI as We Know It

Aug 19, 2026 850 views

After an extended eight-month wait, Microsoft has released a patch to address a severe security vulnerability in its AI assistant, Copilot. This flaw, dubbed CoSnitch, exploits the assistant's shortcomings in differentiating between data and instructions within queries.

Identified by Varonis, CoSnitch represents a culmination of multiple vulnerabilities in Copilot. This is the third significant flaw revealed by Varonis in recent months, following issues like Reprompt and SearchLeak, which highlighted Copilot's susceptibility to running instructions without user consent. All three vulnerabilities share a common trait: one click on a seemingly harmless link could lead to significant security breaches.

Varonis detailed the CoSnitch vulnerability, which relies on exploiting three separate issues within Copilot:

  • Automatic prompt execution: An attacker can exploit a specific parameter in a URL to trigger a prompt execution without any user interaction. This effectively means that a single link could compromise the system immediately.
  • Data exfiltration to external servers: Through crafted prompts, an attacker may access sensitive information from connected applications like Gmail or OneDrive and send that data to an external webhook, entirely hidden from the user.
  • Persistent memory poisoning: By creating malicious web pages, attackers can inject instructions into Copilot’s permanent storage, which endure even after routine security measures like password changes or session resets.

A notable aspect of this vulnerability is how it was uncovered. Varonis interacted with Copilot, prompted it to explain why certain auto-execution features shouldn't work, and in the process, the AI assistant inadvertently revealed details about its architecture. This exchange shed light on undocumented parameters that led to the successful execution of the malicious prompt without any user action needed.

Microsoft's Response and Awareness Concerns

In response to the discovery, Microsoft issued a statement confirming that their users are now protected and do not need to initiate any actions for the fix. The company has also updated its security measures, adamantly asserting their commitment to improving Copilot's defenses. However, the phrasing of Microsoft's statements raises eyebrows, particularly the claim that “enterprise customers using Microsoft 365 Copilot are not affected.”

This assertion lacks nuance, as many enterprise environments may also host personal versions of Copilot, thereby leaving a window open for exploitation of the identified vulnerabilities. With plans for merging various Copilot iterations under a unified system dubbed Copilot Fusion, the presence of flaws in the personal version could potentially affect enterprise users once this transition is complete.

The timeline for addressing these vulnerabilities remains perplexing. Varonis reported the CoSnitch issue at the close of December, and though Microsoft initiated a partial fix on February 1, the complete resolution only came through this recent patch. The incremental nature of the repairs suggests a reactive approach rather than a proactive one, raising concerns about the complexities inherent within enterprise ecosystems.

Understanding the Broader Implications

Mark Tauschek, an analyst at Info-Tech Research Group, commented on the methodology employed by Varonis to reveal these vulnerabilities, describing it as a concerning mix of social engineering combined with prompt injections. The scenario we face is reminiscent of macro virus threats from earlier digital eras; Tauschek urges CISOs to consider disabling Copilot entirely until further mitigations can be solidified.

Aman Mahapatra of Tribeca Softtech further illuminated the underlying challenges. He pointed out a perilous dichotomy: fixes that enhance security may strip away features that render Copilot attractive to users. The ongoing negotiation between product integrity and security necessities complicates quick resolutions to vulnerabilities like CoSnitch. Mahapatra stressed that in systems as dynamic as Copilot, legitimate actions can sometimes mirror malicious intents, muddying the waters for traditional security frameworks.

The memory poisoning aspect, in particular, poses long-term risks. Given that Copilot retains injected prompts over numerous sessions, even robust incident-response strategies fall short of rooting out these threats for good.

Flavio Villanustre, CISO for LexisNexis Risk Solutions Group, echoed similar sentiments, highlighting the architectural limitations inherent in current AI models. The fundamental inability of large language models to distinguish between instructive commands and harmful data streams underscores the urgent need for a redesign in how AI interprets and processes inputs.

The insights from this incident emphasize a pressing call for a careful reevaluation of how AI security is managed. It’s becoming clear that as systems evolve, traditional security measures must also advance to deal with uniquely complex vulnerabilities that arise directly from the technology's inherent functionality.

This article originally appeared on Computerworld.

Source: David Martinez · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Microsoft finally patches critical one-click Copilot vuln...