One Click on Copilot Could Have Leaked Your Connected Apps, Researchers Say

Three flaws in Microsoft Copilot Personal, nicknamed CoSnitch, let a booby-trapped link quietly pull data from Gmail, calendars and other services the assistant was connected to.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A Copilot AI assistant interface on screen showing connected applications like Gmail and calendar services, with warning indicators highlighting data leakage vu
Share

Key points

  • Varonis Threat Labs disclosed three flaws in Microsoft Copilot Personal that together let a single click on a poisoned link steal data from services the user had linked to the assistant.
  • The researchers named the chain CoSnitch and said it worked silently, without any further prompt or warning to the victim.
  • One of the flaws relied on an undocumented URL parameter that Copilot itself revealed to the researchers during testing.
  • Microsoft has addressed the issues on the service side, so ordinary users don't need to install a patch.
  • The bugs affected Copilot Personal, the free consumer version, not the separate Microsoft 365 Copilot product used inside company tenants.

Researchers at Varonis have published details of three bugs in Microsoft Copilot Personal, the free consumer version of Microsoft's AI assistant, that could be strung together to steal data with a single click.

CoSnitch, their name for the chain, fits neatly: the assistant snitched on its own user.

A victim clicks a link that looks harmless. Copilot, running in the background with access to whatever the user had connected (Gmail, Outlook, calendars, files), hands information back to an attacker-controlled destination. No warning banner, no second click, no prompt.

That matters because Copilot Personal is built to reach across a user's digital life. Link your email so it can summarise your inbox and the assistant can read your email. An attacker who hijacks the session inherits that reach.

How did the attack actually work?

The researchers found they could smuggle instructions into Copilot through a crafted web link, then redirect the assistant's answers, along with whatever data it could access, to a server they controlled.

One piece of the puzzle was an undocumented URL parameter, a hidden setting in a web address that Microsoft had never published. Varonis says Copilot surfaced that parameter during testing, essentially briefing the researchers on a control the public wasn't meant to know about. It's a wonderfully on-brand way for an AI assistant to betray a secret.

Chained with two other weaknesses, that parameter turned a normal-looking link into a silent data pipe. The technique is a variant of prompt injection, where hostile text hidden in a page or document tricks the AI into following an attacker's instructions rather than the user's. Our 30 July report on hidden prompts hijacking Microsoft 365 Copilot through Word files showed the same basic mechanic at work inside the enterprise product.

Who was at risk?

Anyone using Microsoft Copilot Personal with third-party apps connected to it. The broader the access (calendars, mail, cloud storage), the bigger the potential haul from a single click.

Microsoft 365 Copilot, the enterprise product, wasn't named in the Varonis writeup. IT teams should still pay attention, because an assistant with broad delegated access being hijacked by untrusted content is a category problem, not a product-specific one. Varonis disclosed the issues to Microsoft, which fixed them server-side. There's no update for users to install.

What should ordinary users do now?

Nothing urgent, but a quick tidy-up is worth the time.

Open Copilot's settings and review which apps it can reach. If you connected Gmail two years ago to test a feature and never used it again, disconnect it. The principle is the same as with any app permission: give it the least access it needs to be useful.

This wasn't a case where multi-factor authentication, the extra login code sent to your phone, would have helped. The attack rode on top of a session the user had already authenticated into. That's the uncomfortable truth about assistant-style products: once you've signed in, the AI is you, as far as connected services are concerned.

Prompt injection is now a routine vulnerability class, and every vendor wiring an AI into additional services is quietly expanding the blast radius when one of these flaws lands. Atlassian's Rovo assistant faced a near-identical pattern in August. Expect more.

Common questions

Do I need to install anything to be safe?

No. Microsoft fixed the flaws on the service side, so there's no user update. Reviewing which apps you've connected to Copilot is still a sensible habit.

Is Microsoft 365 Copilot at work affected too?

Varonis's report focused on Copilot Personal, the consumer version. The same style of attack, hostile text hijacking an AI assistant's session, is a known risk across all such tools, so IT teams should monitor vendor advisories.

© 2026 Threat Vectr