{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/varonis-cosnitch-copilot-personal-2026/",
 "asOf": "2026-09-26",
 "id": "varonis-cosnitch-copilot-personal-2026",
 "date": "2026-08-18",
 "datePrecision": "day",
 "title": "CoSnitch: one-click prompt injection in Copilot Personal exposed connected-app data (CVE-2026-24301)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Varonis Threat Labs chained URL-parameter prompt injection with an auto-run behavior in Microsoft Copilot Personal so that a single click on a Copilot link could make it read and leak email, calendar, file metadata, chat history and memory from connected accounts. Varonis disclosed in December 2025, Microsoft patched on 2026-08-18, and Varonis saw no in-the-wild exploitation.",
 "whyItMatters": "Consumer assistants linked to third-party accounts via OAuth expose those accounts to a single malicious link.",
 "actors": [
  "varonis",
  "microsoft"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "credentials",
  "memory"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.varonis.com/blog/cosnitch",
   "publisher": "Varonis",
   "title": "CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower",
   "date": "2026-08-18",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html",
   "publisher": "The Hacker News",
   "title": "Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps",
   "date": "2026-08-18",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Varonis describes it as the third single-click Copilot flaw it found in 2026, after Reprompt and SearchLeak.",
   "locator": "Varonis post, related vulnerabilities"
  },
  {
   "fact": "The Hacker News reports memory-based persistence survives password changes until the memory entry is deleted.",
   "locator": "THN, impact section"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "indirect-prompt-injection",
  "memory-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}