Varonis Threat Labs discovered three vulnerabilities in Microsoft Copilot Personal that enable attackers to exfiltrate data from connected applications through a single malicious link click. The researchers collectively labeled these flaws CoSnitch.
The attack exploits an undocumented URL parameter that Copilot itself exposes. When a victim clicks a crafted link, the vulnerability silently extracts data from any app connected to the user's Copilot session without triggering visible warnings or user consent prompts. This includes sensitive information accessible through integrations with productivity tools, cloud services, and other third-party applications linked to the assistant.
The attack surface stems from how Copilot handles URL parameters and session permissions. The undocumented parameter allows threat actors to bypass normal authentication checks and directly access resources within the victim's connected ecosystem. Since the data exfiltration occurs silently in the background, users remain unaware their information has been compromised.
The severity of these vulnerabilities lies in their low barrier to exploitation. An attacker needs only to craft a malicious link and distribute it via email, chat, or social media. A single click initiates the data theft. No additional user interaction, installation, or technical knowledge is required from the attacker's perspective.
Organizations using Copilot Personal with connected business applications face elevated risk. Employees who click malicious links could expose customer data, internal documents, credentials, and other sensitive information stored across integrated platforms. The silent nature of the exfiltration means breach detection becomes significantly harder.
Varonis responsibly disclosed the vulnerabilities to Microsoft ahead of public announcement. Organizations should monitor their Copilot deployments and review which applications have Copilot integration enabled. Users should exercise heightened caution with links from untrusted sources, particularly those directing to Copilot sessions or containing unusual URL parameters. Microsoft has not
