// Microsoft 365HIGH
Varonis Threat Labs disclosed CVE-2026-24301 (CoSnitch), three vulnerabilities in Microsoft Copilot Personal allowing silent data exfiltration from connected apps via single-click crafted links. The flaws exploit automatic prompt execution and connected service access to extract mail metadata, calendar details, file information, and conversation history. Microsoft released patches on August 18, 2026; no wild exploitation observed.
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate (opens in a new tab)
- Critical Microsoft Copilot CoSnitch Vulnerability Lets Attackers(opens in a new tab)
// Get alerts for Microsoft 365