Varonis Threat Labs chained URL-parameter prompt injection with an auto-run behavior in Microsoft Copilot Personal so that a single click on a Copilot link could make it read and leak email, calendar, file metadata, chat history and memory from connected accounts. Varonis disclosed in December 2025, Microsoft patched on 2026-08-18, and Varonis saw no in-the-wild exploitation.
Why it matters
Consumer assistants linked to third-party accounts via OAuth expose those accounts to a single malicious link.
Key facts
As stated in the sources, with where to find them.
- Varonis describes it as the third single-click Copilot flaw it found in 2026, after Reprompt and SearchLeak.Varonis post, related vulnerabilities
- The Hacker News reports memory-based persistence survives password changes until the memory entry is deleted.THN, impact section
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Aug 6, 2025
Apr 30, 2026
Jun 11, 2025
Jun 11, 2025
Nov 20, 2025
Oct 31, 2025