• Tech Tech

'CoSnitch' flaw let researchers trick Microsoft Copilot into leaking data, poisoning memory

"The AI exposed the weakness during normal use."

A smartphone displaying the word "Copilot" with an abstract AI circuit background.

Photo Credit: Getty Images

A newly disclosed flaw in Microsoft Copilot Personal shows how an AI assistant can become a security risk when it is pushed to explain its own weak points.

By drawing on technical guidance from Copilot itself, the researchers said they learned how to automatically trigger a malicious prompt, then used that approach to extract information from linked accounts and alter the bot's long-term memory.

Here's what to know

According to The Register, the vulnerability was found by Varonis Threat Labs, which dubbed it "CoSnitch" and reported it to Microsoft in December 2025.

Rather than uncovering the issue through conventional technical analysis, the team said it kept pressing Copilot to explain why a prompt-injection approach supposedly could not work until the assistant's answers exposed enough detail to make the exploit feasible.

They call that strategy "meta-hacking," saying the key was to socially engineer the AI's reasoning process rather than reverse-engineer the system in the usual way.

In the team's words: "What makes CoSnitch unique is how Copilot surfaced its own vulnerabilities. Our researchers didn't have to reverse-engineer the flaw. The AI exposed the weakness during normal use."

Varonis said Copilot disclosed a previously undocumented parameter, autorun=1, and outlined the conditions under which it could be used with a ?q= query to make a prompt run automatically.

That, the researchers said, means an attacker could send a malicious link through email, text, or a QR code and then gain access to session context, emails, messages, and connected apps without any obvious warning.

More background

AI assistants are increasingly tied into the tools people use every day, from inboxes and calendars to file storage and chat histories.

If a single compromised prompt can activate those connections, the threat goes far beyond a chatbot giving a bad answer.

Varonis said the problem was not about breaking into some hidden internal vault. It was about misusing the legitimate access Copilot already had.

As the team put it, "This is not a hack of Copilot's internal memory; it is Copilot doing exactly what it was designed to do: reading user data and holding it in context."

These systems can help utilities forecast electricity demand, improve building efficiency, and optimize the integration of renewable energy into the grid.

At the same time, running large AI models consumes significant amounts of electricity and water, and when these tools are misused or deployed insecurely, the consequences can ripple through households in the form of higher bills, service strain, or privacy risks.

Lior Adar, senior security researcher at Varonis, said that even though this case involved a personal AI product, it points to deeper design concerns that could carry into workplace systems.

What's being done?

Microsoft said users do not need to take action.

In a statement, a Microsoft spokesman said, "Our customers are already protected and do not need to take any action. We continuously update our guardrails to strengthen our protections against similar techniques."

Connecting AI assistants to sensitive services and clicking unexpected links, even if they appear to open a familiar platform, can increase exposure.

The more apps an assistant can access, the more damage a malicious prompt can cause.

"These novel attack chains do more than just exfiltrate user data. I tricked the assistant into leaking sensitive internal parameters and configuration details," Adar said. "Exposing these backend mechanics gives attackers a blueprint of the AI's internal logic for Automatic Prompt Execution."

Where can I learn more?

The Copilot case is part of a broader pattern in AI: weak safeguards, rushed rollouts, and overreliance on generated output can all create real problems.

The stories below show how those issues are playing out in everything from safety debates to very public editorial blunders.

• At leading AI companies, dangerously overlooked flaws are fueling fears about superintelligent systems.

• Across the industry, a very significant jump in AI risks is intensifying calls for regulation.

• At the Chicago Sun-Times, an AI-generated fake reading list left editors completely embarrassed.

AI safety is already a practical problem, not some distant hypothetical. The same shortcuts that lead to cringe-worthy mistakes can also create openings for far more serious security failures.

Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.

Cool Divider