Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Read full story on The Hacker News
Share
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
AI disclosure

Summary

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.