The safest way to keep a secret is to never explain why it is safe. Microsoft Copilot did not get that memo.
A one-click flaw called CoSnitch
CoSnitch, tracked as CVE-2026-24301, affected Microsoft Copilot Personal and could be triggered with nothing more than a victim clicking a single malicious link. From there it silently pulled sensitive data out of the victim’s connected accounts, no follow-up interaction required. Varonis Threat Labs reported it to Microsoft in December 2025, and Microsoft says it found no evidence the flaw was exploited before the patch shipped on August 18, 2026, which still leaves an eight-month gap between disclosure and fix for a bug rated critical.
How researchers found it: they asked the AI to prove them wrong
The detail that makes CoSnitch worth reading about is the discovery method. Varonis researchers asked Copilot to explain why a suspected attack path would not work. Copilot’s own explanation, intended to demonstrate the exploit was infeasible, ended up describing its internal architecture in enough detail to reveal the exact undocumented parameter an attacker would need. Varonis calls this “meta-hacking”: rather than attacking Copilot’s code, you social-engineer its reasoning process into handing you the blueprint. It is a very different failure mode from a traditional buffer overflow or injection bug, and it is one that conventional code review will not catch.
Not a one-off
CoSnitch is the third Copilot vulnerability Varonis has disclosed in 2026, following Reprompt, which bypassed Copilot’s safety guardrails simply by asking the same question twice, and SearchLeak, which turned Microsoft 365 Copilot Enterprise into a covert exfiltration channel. Three distinct bypasses in one product line in one year is a pattern, not a coincidence, and it says something specific about how AI assistants fail: their guardrails are reasoning-based, and reasoning can be talked around in ways a firewall rule cannot.
What this means if Copilot touches your business
European organisations that have rolled out Microsoft 365 Copilot or Copilot Personal are trusting it with access to email, files, and other connected accounts. Traditional application security testing was not built to probe for this class of flaw, where the vulnerability lives in what the model will say rather than in a line of exploitable code. If your AI assistant deployment has not had its guardrails, connected-account scopes, and prompt-handling behaviour independently reviewed, CoSnitch is a preview of the kind of gap that review would need to find.
If you want your Copilot or other AI assistant rollout assessed for this kind of exposure, or need help defining what data these tools should and should not be allowed to touch, contact Excello Digital. We help European businesses adopt AI tools without adopting their blind spots.
