# Microsoft's Copilot Told Researchers How to Hack It


The vulnerability that Varonis researchers stumbled into while probing Microsoft Copilot Personal has a detail that deserves more attention than the headline: the AI assistant effectively handed them the key.


While investigating the product, Varonis Threat Labs found an undocumented URL parameter embedded in links that Copilot generated itself. That parameter became one of the building blocks for three chained flaws — now collectively named CoSnitch — that let an attacker craft a single malicious link capable of silently exfiltrating data from any app connected to the victim's Copilot session.


The AI didn't just have vulnerabilities. It helped reveal how to weaponize them.


## One Click, Many Inboxes


The attack path Varonis describes is uncomfortable in its simplicity. A target receives a link — in a chat, an email, a document — and clicks it. No credentials prompted. No warning. Copilot, which may be connected to the victim's email, calendar, OneDrive, Teams history, and third-party integrations, silently hands that session's accessible data to the attacker.


CoSnitch doesn't require the victim to do anything unusual. Clicking links is what people do. The threat model here isn't "sophisticated phishing that tricks someone into running a macro" — it's the kind of interaction that happens a hundred times a day in a corporate environment.


That's the point Varonis is making with the name. CoSnitch: your AI assistant, snitching on you without knowing it.


## The Aggregator Problem


Microsoft Copilot Personal isn't unique in the category it occupies. Google's Gemini, OpenAI's ChatGPT with connected apps, Anthropic's Claude through integrations — all of these products are fundamentally data aggregators with a natural-language interface on top. They are valuable precisely because they can reach across siloed systems and pull context together. That utility is also the threat surface.


When a traditional browser extension had access to your Gmail, the risk was contained to that extension's permissions. When a Copilot-like assistant has access to your email, calendar, documents, CRM, and ticketing system simultaneously, a single exploitable flaw in the assistant becomes a single point of failure for all of it.


This is the security debt that shipped with every "AI assistant connected to your entire work life" product announcement of the last two years. The features were real. The threat modeling, apparently, lagged.


Prior research in this space has mostly focused on prompt injection — tricking an AI into performing actions on a user's behalf by embedding instructions in content the AI processes. CoSnitch is structurally similar but distinct: it exploits the infrastructure around how the assistant handles URLs, not the model itself. The attack surface isn't the LLM's reasoning. It's the plumbing.


## What Varonis Actually Found


The three flaws Varonis disclosed work in combination. At the center is that undocumented URL parameter — something Copilot itself generated in links, which researchers identified and then probed for exploitability. The parameter, when crafted correctly, allows an external actor to influence what the assistant retrieves and where session data flows.


Varonis has not published full technical details, consistent with coordinated disclosure practices. Microsoft has been notified. At time of publication, it's unclear whether patches have shipped, are in progress, or whether Microsoft contests the severity classification.


What's clear is that the attack requires no elevated permissions, no malware install, and no user action beyond a click. In enterprise environments where Copilot is being deployed at scale — Microsoft has pushed hard on M365 Copilot adoption — the blast radius of a working exploit tracks directly with how deeply the assistant is integrated.


## What Gets Exfiltrated


The Varonis disclosure describes data "from connected apps and other information available to the victim's Copilot session." In practice, depending on the victim's configuration, that could include email contents, calendar entries, SharePoint documents, Teams messages, and outputs from any third-party connectors the organization has enabled.


Copilot Personal and Copilot for M365 have different permission scopes, but the underlying architecture shares design patterns. Researchers and defenders should not assume a vulnerability disclosed against the consumer product has no bearing on enterprise deployments.


---


## HackWire Analysis


The CoSnitch disclosure lands at a moment when enterprise AI assistant adoption has well outpaced the security community's ability to audit it. Security teams that spent the last 18 months asking "should we allow Copilot?" are now being asked to secure deployments that are already running.


The detail that keeps nagging: the undocumented URL parameter was surfaced by the assistant itself. This is a recurring problem with AI products that ship fast — the attack surface isn't always something an engineer consciously built. It's residue. A parameter added for telemetry, or debugging, or an A/B test that never got cleaned up, now living inside links that the AI generates and users click without thinking.


The broader pattern here is what I'd call the aggregation trap. Every productivity AI product currently being sold to enterprises is monetized on its ability to synthesize information across the widest possible data surface. The security model assumes that access controls on the underlying systems are sufficient. CoSnitch demonstrates they're not — because the assistant becomes a credential-holding intermediary that an attacker can redirect.


Defenders should be doing three things right now: auditing which Copilot integrations are enabled, reviewing whether Copilot-generated links appear in outbound communications (and could be spoofed), and applying least-privilege principles to what apps are connected. Waiting for Microsoft's patch is not a posture.


The larger question nobody is asking loudly enough: who is responsible for the security of AI-generated content? If the assistant produces a link and that link becomes an attack vector, is that a product vulnerability, a misconfiguration, or something new entirely? CoSnitch suggests we need an answer before the next one ships.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)