Skip to content
theregister·

🚨Microsoft Copilot Vulnerability Exposed: CoSnitch Allows Full Access

Copilot's CoSnitch lets attackers steal your data and more

TL;DR

A critical security flaw, dubbed 'CoSnitch', allows attackers full access to a victim's session context through URL parameters. Attackers can exfiltrate sensitive information without user interaction.

Microsoft Copilot Personal has been exploited by researchers using a vulnerability named CoSnitch, allowing them to execute commands and gain unauthorized access to user sessions via URL parameters. This flaw could lead to data exfiltration, disinformation injection attacks, and reconnaissance on connected apps. The attack works silently without visible confirmation or user interaction, making it hard to detect. Microsoft plans to patch this issue formally identifying the CVE in December 2025.

Microsoft Copilot Vulnerability Exposed: CoSnitch Allows Full Access — theregister

Key Points

1

CoSnitch vulnerability allows attackers to execute commands using ?q= and ?autorun=1 parameters in URLs.

2

Attackers can exfiltrate sensitive information like emails, credentials, and chat history without user interaction or visible confirmation.

3

Microsoft plans to formally identify the CVE and issue a patch on Tuesday, December 2025.

4

The flaw highlights architectural issues with LLMs' lack of strict boundaries between raw data and system instructions.

5

Attackers can poison Copilot's memory, modify future prompts, or perform reconnaissance on connected apps.

Why It Matters

If you're using Microsoft Copilot Personal in your workflow, this vulnerability could expose sensitive information to attackers. The attack works silently without user interaction, making it hard to detect and mitigate.

copilotvulnerabilityco-snitchdata-exfiltrationurl-parameters

Frequently Asked Questions

Why does this matter?

If you're using Microsoft Copilot Personal in your workflow, this vulnerability could expose sensitive information to attackers. The attack works silently without user interaction, making it hard to detect and mitigate.

What happened?

A critical security flaw, dubbed 'CoSnitch', allows attackers full access to a victim's session context through URL parameters. Attackers can exfiltrate sensitive information without user interaction.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,221 builders reading daily.

Also get