One Click on Copilot Could Have Leaked Your Connected Apps, Researchers Say
Three flaws in Microsoft Copilot Personal, nicknamed CoSnitch, let a booby-trapped link quietly pull data from Gmail, calendars and other services the assistant was connected to.

Key points
- Varonis Threat Labs disclosed three flaws in Microsoft Copilot Personal that together let a single click on a poisoned link steal data from services the user had linked to the assistant.
- The researchers named the chain CoSnitch and said it worked silently, without any further prompt or warning to the victim.
- One of the flaws relied on an undocumented URL setting that Copilot itself revealed to the researchers during testing.
- Microsoft has been notified and the issues have been addressed on the service side, so ordinary users do not need to install a patch.
- The bugs affected Copilot Personal, the free consumer version, not the separate Microsoft 365 Copilot product used inside company tenants.
Researchers at Varonis have published details of three bugs in Microsoft Copilot Personal, the free consumer version of Microsoft's AI assistant, that could be strung together to steal data with a single click.
They are calling the chain CoSnitch. The name fits: the assistant, in effect, snitched on its own user.
The attack worked like this. A victim clicks a link that looks harmless. Copilot, running in the background with access to whatever the user had connected to it (think Gmail, Outlook, calendars, files), quietly hands information back to an attacker-controlled destination. No extra prompt. No warning banner. No second click.
That matters because Copilot Personal is designed to be helpful across a user's digital life. If you have linked your email so it can summarise your inbox, the assistant can read your email. An attacker who hijacks the assistant's session inherits that reach.
How did the attack actually work?
The short version: the researchers found they could smuggle instructions into Copilot through a crafted web link, and then send the assistant's answers, along with data it had access to, out to a server they controlled.
One piece of the puzzle was an undocumented URL parameter, a hidden setting tucked inside a web address that Microsoft had not published anywhere. Varonis says Copilot itself surfaced the parameter during testing, essentially telling the researchers about a control the public was never meant to see. That is a wonderfully on-brand way for an AI assistant to leak a secret.
Chained with two other weaknesses, that parameter let the attacker turn a normal-looking link into a silent data pipe. The technique is a variant of what the industry calls prompt injection, where hostile text hidden in a page or document tricks the AI into following the attacker's instructions instead of the user's.
Who was at risk?
Anyone using Microsoft Copilot Personal with third-party apps connected to it. The more services a user had wired up, calendars, mail, cloud storage, the bigger the potential haul from a single click.
The enterprise product, Microsoft 365 Copilot, was not named in the Varonis writeup. Companies running Copilot inside their own Microsoft 365 tenants should still take note, because the underlying pattern (an assistant with broad delegated access being tricked by untrusted content) applies across the whole category.
As first reported by The Hacker News, Varonis disclosed the issues to Microsoft, which has addressed them on its side. There is no update for users to install.
What should ordinary users do now?
Nothing urgent, but a small tidy-up is worth the ten minutes.
Open Copilot's settings and review which apps and accounts it can reach. If you connected Gmail two years ago to test a feature and never used it again, disconnect it. The rule with AI assistants is the same as with any app permission: give it the least it needs to be useful to you.
This was not a case where multi-factor authentication, the extra login code sent to your phone, would have helped. The attack rode on top of a session the user had already signed into. That is the awkward truth about assistant-style products: once you have authenticated, the AI is you, as far as the connected services are concerned.
Expect more bugs of this shape. Prompt injection is now a routine class of vulnerability, and every vendor racing to plug an AI into everything else is, quietly, expanding the blast radius when one of these flaws lands.
Common questions
Do I need to install anything to be safe?
No. Microsoft fixed the flaws on the service side, so there is no user update. Reviewing which apps you have connected to Copilot is still a sensible habit.
Is Microsoft 365 Copilot at work affected too?
Varonis's report focused on Copilot Personal, the consumer version. The same style of attack, hostile text hijacking an AI assistant, is a known risk across all such tools, so IT teams should keep an eye on vendor advisories.



