Updated
Updated · Computerworld · Aug 19
Microsoft Closes Critical CoSnitch Copilot Flaw After 8 Months as Researchers Warn Enterprise Risk
Updated
Updated · Computerworld · Aug 19

Microsoft Closes Critical CoSnitch Copilot Flaw After 8 Months as Researchers Warn Enterprise Risk

3 articles · Updated · Computerworld · Aug 19

Summary

  • Eight months after confirming the issue, Microsoft on Tuesday completed a fix for the critical CoSnitch flaw in Copilot Personal, saying customers are already protected and need take no action.
  • Varonis said one legitimate-looking link could chain three weaknesses—automatic prompt execution, data exfiltration from connected apps, and persistent memory poisoning—because the LLM could not reliably separate data from instructions.
  • Copilot itself helped expose the bug: Varonis said repeated follow-up questions during refusals led the assistant to disclose an undocumented URL parameter that enabled prompts to run on page load without user confirmation.
  • Microsoft said Microsoft 365 Copilot enterprise customers were unaffected, but analysts warned personal Copilot accounts inside workplaces and the planned Copilot Fusion unification could carry similar risk into enterprise environments.
  • Security experts said CoSnitch highlights a broader AI design problem: the same agentic features vendors market as useful can also enable abuse, making such flaws hard to eliminate rather than merely mitigate.

Insights

How did an AI assistant accidentally teach hackers to bypass its own security and steal enterprise passwords with a single click?
What happens when an enterprise AI combines old web bugs into a new weapon that bypasses traditional anti-phishing defenses entirely?