Image credit: Microsoft
Microsoft has fixed a Copilot flaw that let a single click hand an attacker a user's email, calendar, and chat history. The flaw, which security firm Varonis Threat Labs disclosed and nicknamed CoSnitch, affected Copilot Personal, the free consumer version of Microsoft's AI assistant. Varonis said it reported the issue to Microsoft in December 2025, and Microsoft shipped a final fix yesterday, August 18.
If you've connected Copilot to Gmail, Google Drive, Google Calendar, Outlook, or OneDrive so it can search your files or check your schedule for you, an attacker needed just one click to reach that data. According to Varonis, a specially crafted link would open Copilot in your already-signed-in browser session and immediately run a hidden command with the same access you'd granted the assistant yourself, no confirmation screen or second click required.
From there, Varonis showed Copilot pulling full email bodies, including passwords typed into messages, along with calendar details, file names from Drive, and saved chat history, then sending that data to a server the attacker controlled without triggering any alerts. Microsoft's own support documentation says its connectors don't expand what data Copilot can reach beyond what your account already permits. The researchers said they found no evidence the flaw was exploited before Microsoft's fix went out.
This is the third Copilot flaw of this kind Varonis has found this year, following Reprompt, which Techlicious covered in an earlier disclosure, and a separate flaw called SearchLeak affecting the workplace version of Copilot. Each relied on the same weakness: getting Copilot to treat an attacker's hidden instructions as if it was typed by the user.
Microsoft's fix is already live, so the specific attack Varonis demonstrated no longer works. Still, it's worth opening Copilot's connector settings and disconnecting any service you're not actively using. And treat any link that opens an AI assistant showing a pre-typed question the same way you'd treat a link in an unexpected text message: don't click it if you don't recognize where it came from.
Read next: How to protect your privacy on public Wi-Fi