TechNewsReel
Live

Microsoft Copilot 'CoSnitch' flaw enables zero-click prompt injection

Varonis Threat Labs discovered a vulnerability allowing attackers to execute commands in authenticated sessions via undocumented URL parameters.

TechNewsReel Newsroom · August 18, 2026

Microsoft is preparing to patch a critical vulnerability in Copilot Personal that allows attackers to execute prompt injections without any user interaction. The flaw, dubbed "CoSnitch," was uncovered by Varonis Threat Labs and leverages the AI's own internal logic to bypass security boundaries.

The attack utilizes a combination of the `?q=` query parameter and an undocumented `?autorun=1` parameter. By combining these, a malicious actor can craft a URL that automatically executes a prompt the moment a victim loads the page. According to Varonis, the vulnerability can be delivered through common social engineering vectors, including SMS, email phishing, or QR codes. Once triggered, the prompt runs within the victim's authenticated session, allowing the attacker to potentially poison the AI's memory or exfiltrate sensitive data.

The mechanics of 'meta-hacking'

The discovery of CoSnitch resulted from a technique the researchers call "meta-hacking." Rather than guessing the system's weaknesses, the team social engineered Copilot into revealing its own undocumented parameters. Lior Adar, a senior security researcher at Varonis, stated that these attack chains allowed him to trick the assistant into leaking sensitive internal parameters and configuration details. Varonis Threat Labs noted that the AI effectively exposed its own weakness during normal use, providing a blueprint of its internal security gaps.

This vulnerability highlights a systemic issue in Large Language Models (LLMs): the lack of strict boundaries between raw data and system instructions. While Microsoft had previously attempted to harden the assistant against prompt injection by disabling certain parameters, the AI's inherent helpfulness was weaponized to reveal the remaining holes in its architecture.

Industry implications

The risk associated with CoSnitch is amplified by the deep integration of Copilot into user ecosystems. Because the assistant often has authorized access to a user's connected apps, files, and emails—including services like Gmail and Google Drive—a successful zero-click attack can bypass traditional firewalls and authentication. This creates a direct path for the exfiltration of private corporate or personal data without the user ever typing a command.

Path to remediation

Varonis reported the flaw to Microsoft in December 2025. The company is scheduled to release a formal patch and a CVE identifier on Tuesday, August 19, 2026. Security professionals are advised to monitor for the official update to mitigate the risk of automated prompt injection attacks targeting authenticated Copilot sessions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.