CVE-2026-24301Disclosure(microsoft / copilot)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch microsoft copilot systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • copilot

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 37 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 23 signals
  • Disclosure: 17 classified signals
  • General: 4 classified signals
  • Peaked 9d ago at 12 mentions (2026-08-19); latest day: 1
  • 37 total mentions across 11 days

Affected systems

Vendors
Products
copilot

1 version affected across 1 product

Deep dive

Activity timeline37 mentions / 11d
036912Mentions · 2026-08-18: 4Mentions · 2026-08-19: 12Mentions · 2026-08-20: 8Mentions · 2026-08-21: 4Mentions · 2026-08-23: 2Mentions · 2026-08-24: 1Mentions · 2026-08-25: 2Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-09-01: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-08-18: 2PoC Mentioned / Linked · 2026-08-19: 3PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-09-01: 1Active Exploitation · 2026-08-28: 1Patch / Workaround · 2026-08-18: 3Patch / Workaround · 2026-08-19: 6Patch / Workaround · 2026-08-20: 3Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-08-18: 4Technical Details · 2026-08-19: 7Technical Details · 2026-08-20: 3Technical Details · 2026-08-21: 3Technical Details · 2026-08-25: 2Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-02: 108-1808-1908-2008-2108-2308-2408-2508-2708-2809-0109-02
Signal classification5 categories
Disclosure
1745.9%
Patch
1232.4%
General
410.8%
PoC
38.1%
Active Exploitation
12.7%
Referenced assets19 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-184
Disclosure1Patch2PoC1
2026-08-1912
Disclosure6General1Patch4PoC1
2026-08-208
Disclosure5General1Patch2
2026-08-214
Disclosure3Patch1
2026-08-232
General2
2026-08-241
Patch1
2026-08-252
Patch1PoC1
2026-08-271
Patch1
2026-08-281
Active Exploitation1
2026-09-011
Disclosure1
2026-09-021
Disclosure1
Full discourse20 posts
  • Minh Phu | Tech & AI@ChauPhu999
    Patch

    MICROSOFT VÁ KHẨN LỖ HỔNG "COSNITCH" - NGUY CƠ RÒ RỈ DỮ LIỆU NHẠY CẢM 🔓🚨 Microsoft đã phát hành bản vá ngày 18/8 cho lỗ hổng CVE-2026-24301, được các chuyên gia của Varonis Threat Labs đặt tên "CoSnitch", cảnh báo nguy cơ rò rỉ thông tin nghiêm trọng nếu không cập nhật kịp thời. Người dùng Windows nên kiểm tra và cài đặt bản vá ngay lập tức! #Microsoft #BaoMat #CoSnitch #Thứ5

    Post summary

    Microsoft issued a patch on 18/8 for CVE-2026-24301 (CoSnitch), urging Windows users to update promptly to mitigate potential data leakage.

    1410140163
    11.9K followersView on X
  • Es Geeks@EsGeeks
    Patch

    🚨 COPILOT PERSONAL: un solo clic basta para robar correos, archivos y memoria del asistente. Varonis reveló CoSnitch (CVE-2026-24301). Microsoft ya parcheó hoy. Revisa tus conexiones y borra memorias dudosas. #Copilot #Ciberseguridad #IA https://t.co/Oj7OhPHtmD

    Post summary

    Varonis disclosed CVE‑2026‑24301, enabling theft of emails, files, and memory, and Microsoft has released a patch today; users are advised to inspect connections and remove suspicious memory.

    140103858
    22.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    😨 meta-hacking : de l'ingénierie sociale appliquée à l'IA elle-même. CoSnitch -> Copilot a lui-même livré la faille qui permet de voler vos données Si vous souhaitez en savoir plus, voici mon article à ce sujet : - https://www.it-connect.fr/cosnitch-cve-2026-24301-copilot-personal-faille-un-clic/ #ia #copilot #microsoft https://t.co/5SuCugAcEA

    Post summary

    The post announces the discovery of CVE‑2026‑24301 in Microsoft Copilot, pointing to an article that presumably contains further details about the vulnerability.

    04073707
    11.7K followersView on X
  • 山下達朗|Nishika CEO@tatsulowyamash1
    Disclosure

    Microsoft CopilotのPersonalに深刻な脆弱性「CoSnitch」(CVE-2026-24301)が発覚。悪意あるリンクを1クリックするだけで、連携中のGmail・Drive・Calendarのデータが外部に送信される恐れがあったという戦慄の事態。 https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html

    Post summary

    The article reports the discovery of CVE-2026-24301, a serious vulnerability in Microsoft Copilot Personal that would allow a malicious link to exfiltrate Gmail, Drive, and Calendar data, but it does not include PoC details, exploit code, patch information, or evidence of active exploitation.

    30050226
    385 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Patch

    Microsoft Copilot(個人向け)を使っている人は、一度メモリ設定を確認してください。 8月18日、個人向けMicrosoft Copilotに影響する脆弱性「CoSnitch(CVE-2026-24301)」が修正されました。 ただし、修正されたから終わり、とは言い切れません。 ■ 何が起きるか 今回公表されたのは、大きく2つの攻撃経路です。 1つ目は、細工されたリンクを1クリックするだけで、Copilotセッション内で攻撃者の指示を実行させるもの。 接続されていたメール、カレンダー、Google Drive、過去の会話などから情報を取得し、外部へ送信できることが実証されています。 しかも、処理が始まった後はタブを閉じても止まらないケースがありました。 もう1つは、さらに厄介です。 細工されたWebページをCopilotに「要約」させると、そのページに埋め込まれた指示がCopilotのメモリへ保存される可能性がありました。 つまり、その場だけのプロンプトインジェクションではなく、 攻撃者の指示が、次の会話、その次の会話にも残り続ける。 パスワードを変更しても、PCを交換しても、Copilot側のメモリに残っていれば消えません。 ■ 対象 今回公表された対象は、http://copilot.microsoft.com の個人向けMicrosoft Copilotです。 Microsoft 365 Copilotに同じ脆弱性が存在した、という報告ではありません。 また、現時点で実際の攻撃に悪用された証拠は確認されていません。 ■ やること ① Copilotのメモリ設定を開き、身に覚えのない内容や指示がないか確認 ② 不審なメモリがあれば削除。細工されたページなどからメモリが汚染された可能性があるため、過去の利用状況も確認 ③ Copilotに接続しているメール、Google Drive、カレンダーなどを棚卸しし、不要な連携は解除 ④ 過去に怪しいリンクをCopilot経由で開いた心当たりがある場合は、接続先サービス側のアクセス履歴や不審な操作も確認 ここが重要です。 Copilotのメモリを確認して分かるのは、メモリ汚染の有無です。 一方、1クリック型のデータ取得は別の攻撃経路です。 そのため、メモリに異常がなくても、怪しいリンクを開いた心当たりがあるなら、Copilotだけを見るのではなく、接続していたメール、Drive、カレンダーなどの側も確認する必要があります。 今回の脆弱性は8月18日にサーバ側で修正されており、ユーザーがインストールする更新はありません。 一方で、修正前に書き込まれたメモリが自動的に遡って削除されたのかは、公表情報からは確認できません。 だから、個人向けCopilotを使っている人は、 メモリを見る。 接続アプリを見る。 怪しいリンクに心当たりがあれば、接続先の履歴も見る。 この3つは、一度確認しておいた方がいいと思います。 AIへの攻撃は、会話が終われば終わるとは限らなくなっています。 出典:The Hacker News / Varonis Threat Labs https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html #MicrosoftCopilot #Copilot #AIセキュリティ #プロンプトインジェクション #サイバーセキュリティ

    Post summary

    Microsoft has fixed CVE‑2026‑24301 in Microsoft Copilot, detailing two attack paths involving malicious links and memory persistence; no active exploitation has been confirmed yet, and users are advised to review Copilot memory and linked services for potential contamination.

    000621.1K
    860 followersView on X
  • えすいー@se_april_2015
    Patch

    #Copilot #CoSnitch CVE-2026-24301   既にMicrosoftは パッチ済との事だが AI研究者が(メタハッキングで) 内部構造をAIに聞いて 発見された脆弱性   AIが参照出来るだけでなく 実行出来るかまで 設計しなければならんのか…   カオスだなー 他のAIも大丈夫か? https://gigazine.net/news/20260819-copilot-leak-own-vulnerability/

    Post summary

    The tweet announces that Microsoft has patched CVE-2026-24301, noting it was discovered by an AI researcher, but provides no exploit details or active usage reports.

    01150614
    252 followersView on X
  • Clint Gibler@clintgibler
    Disclosure

    📢 Sponsor: Meet CoSnitch (CVE-2026-24301), a Microsoft Copilot flaw letting attackers exfiltrate sensitive data with one click via a hidden parameter @Varonis found by tricking Copilot into hacking itself. This is "meta-hacking." See how it happened: https://hubs.ly/Q04vbW3_0

    Post summary

    The statement announces a newly disclosed Microsoft Copilot vulnerability (CVE-2026-24301) that permits data exfiltration via a hidden parameter, linking to a demonstration but providing no exploit code or patch details.

    11030705
    26.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-24301 (critical): Microsoft Copilot Personal's CoSnitch chain turns one link click into silent, cross-app data exfiltration with no anomalous signals for defenders to catch. - CVE-2026-24301 chains three flaws: auto-prompt execution via the undocumented ?autorun=1 URL parameter paired with ?q=, silent OAuth connector exfiltration encoding stolen data as base64 in a URL path fetched by Copilot itself, and indirect prompt injection via web summarization that writes attacker instructions into Copilot's persistent memory store. Patched August 18, 2026. No in-the-wild exploitation confirmed. - The exfil path is forensically invisible: Copilot issues a standard outbound HTTPS GET to an attacker webhook with the payload in the URL path (e.g., GET /exfil/SGV5LCBNe... to eo8el024afgbal3.m.pipedream[.]net). No anomalous headers, no unusual ports. Security tooling sees routine Copilot URL-fetch behavior. - Memory poisoning via web summarization survives password changes, session revocation, and device re-enrollment. The only artifact is an entry in Copilot's memory UI, which most users never inspect and no EDR or SIEM currently flags. - Discovery method is noteworthy: researchers used "meta-hacking," iteratively reframing refusals as follow-up questions until Copilot disclosed an undocumented parameter unprompted. This technique applies to any agentic LLM with a natural language interface. #DFIR_Radar

    Post summary

    The post discloses the CVE-2026-24301 details, notes the official patch date, confirms no in‑the‑wild exploitation, and provides technical description of the flaw chain.

    11021203
    1.8K followersView on X
  • CreedTec@Creed1732
    Disclosure

    2/6 Varonis Threat Labs found CVE-2026-24301 (CoSnitch, CVSS 8.8). A single crafted link with an undocumented parameter could auto-execute a malicious prompt inside the victim’s authenticated session.

    Post summary

    Varonis Threat Labs reports a new CVE-2026-24301 vulnerable to a crafted link that can execute malicious prompts during an authenticated session.

    1101041
    126 followersView on X
  • AIと共創中💻カンボジアチーム@KH_AI_Nakama
    PoC

    Copilot Personalの脆弱性「CoSnitch」(CVE-2026-24301)。研究者の検証で、細工URLのクリックのみで不正操作を実行(追加操作不要)、連携アプリのデータ窃取も確認。パスワード変更等の後も汚染が残る恐れがあるという。 Varonisが昨年12月に報告、修正は8月18日(約8か月後)。悪用の確認例はなし。 https://t.co/0LaJpEBIc6

    Post summary

    Researchers confirmed that clicking a crafted URL triggers unauthorized actions and data theft on Copilot Personal (CVE‑2026‑24301), a PoC was demonstrated, a patch was released in August, but no active exploitation has been reported.

    0002081
    42 followersView on X
  • فيصل بن أحمد | خبير تقني@b_muf9
    General

    🚨 تنبيه سيبراني | CoSnitch خلال متابعتي لتهديدات الـAI، لفتني CoSnitch في Microsoft Copilot. اللافت هو Meta-Hacking بدل استهداف النظام مباشرة يتم استغلال سلوك المساعد لكشف معلومات تدريجيًا عن دفاعاته. CVE-2026-24301 | CVSS 8.8 الخلاصة: كلما زادت صلاحيات الـAI واتصاله بالبيانات… اتسع Attack Surface. لا تراقب الـAI فقط… راقب ما يستطيع الوصول إليه. 🔐

    Post summary

    The post alerts to CVE‑2026‑24301 in Microsoft Copilot, highlighting a meta‑hacking technique that expands the attack surface as AI privileges increase. No PoC, exploit code, patch, or detailed technical data are supplied.

    00011444
    10.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - Microsoft Copilot Web Command Injection Info Disclosure (CVE-2026-24301) Microsoft Copilot (Copilot Web) improperly neutralizes special elements in a command, allowing crafted input to inject command tokens in a network-reachable request flow. An unauthenticated attacker can trigger command execution primitives that result in remote information disclosure. 👉Affected: Microsoft Copilot (Copilot Web) (versions unspecified)

    Post summary

    The post discloses a command injection vulnerability (CVE‑2026‑24301) in Microsoft Copilot Web that permits unauthenticated attackers to execute commands and leak information.

    0001189
    292 followersView on X
  • cyber_updates_365@CyberUpdates365
    Disclosure

    CVE-2026-24301: The "CoSnitch" flaw turns Microsoft Copilot into an insider threat. 🚨 Learn how attackers can manipulate AI to access restricted enterprise data. Mitigation steps: https://cyberupdates365.com/copilot-cosnitch-cve-2026-24301/ #AI #InfoSec #newstreamer

    Post summary

    The post introduces CVE‑2026‑24301 as a flaw affecting Microsoft Copilot and offers mitigation steps, but it lacks technical details, PoC, or exploitation evidence.

    0002093
    22 followersView on X
  • Cybersecurity News Alerts@secureblognews
    General

    Is your Microsoft Copilot leaking company secrets? 🛑 The "CoSnitch" vulnerability (CVE-2026-24301) exposes enterprise AI to severe data exfiltration. Check your risk level: https://cyberupdates365.com/copilot-cosnitch-cve-2026-24301/ #CyberSecurity #Copilot

    Post summary

    The post alerts users to CVE-2026-24301 in Microsoft Copilot, but provides no technical details, exploit code, or mitigation information.

    0002047
    41 followersView on X
  • Cyber_Lens@Aiz_Cyber
    Disclosure

    ⚠️ Microsoft Copilot Personal flaw CVE-2026-24301 could let a crafted link silently execute prompts and exfiltrate data from connected apps within a victim’s authenticated session. Technical details below 👇 #Aiz_Cyber #CVE #AISecurity https://t.co/T24YCETO6L

    Post summary

    Microsoft announced a flaw in Copilot Personal (CVE-2026-24301) that can enable a crafted link to silently execute prompts and exfiltrate data from connected apps while the user is authenticated.

    0002045
    41 followersView on X
  • Devsec AI@devsec_ai
    Disclosure

    @varonis got Microsoft Copilot to explain how to hack itself. Undocumented autorun=1 fired a prompt on page load, then OAuth-connected mail and Drive walked out the door. Patch took eight months. CVE-2026-24301, CoSnitch. #cybersecurity #ai

    Post summary

    The tweet reports the discovery of CVE-2026-24301 in Microsoft Copilot, noting undocumented autorun behavior and OAuth leakage, and mentions that a patch was released after eight months. No PoC or exploit details are provided.

    00010144
    194 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Microsoft Copilot の脆弱性 CVE-2026-24301:ワンクリックで機密情報を窃取する CoSnitch とは? https://iototsecnews.jp/2026/08/19/critical-microsoft-copilot-cosnitch-flaw-lets-hackers-steal-sensitive-data-with-one-click/ 紹介する記事では、Microsoft Copilot Personal における深刻な脆弱性 CVE-2026-24301 (CoSnitch) が解説されています。信頼された連携アプリケーションの権限を悪用され、ワンクリックで機密データが外部へ送信される懸念が存在しました。この問題により、メールやクラウドファイルなどの機密情報漏洩/間接プロンプトインジェクションによるメモリ汚染/永続的な悪意ある命令の維持といった影響が及ぶ危険性がありました。修正プログラムの適用/不要なコネクター連携の解除/不審なリンクの開封防止といった迅速なセキュリティ対策が求められます。 #AI #ML #Copilot #CVE202624301 #Microsoft #Vulnerability

    Post summary

    The post outlines the CVE-2026-24301 flaw in Microsoft Copilot Personal, explains how it can exfiltrate data with one click via trusted app permissions, and recommends applying the patch and disabling connectors to mitigate the threat.

    00010153
    510 followersView on X
  • Kevin Kaminski@kkaminsk
    Patch

    🔒 CoSnitch vulnerability (CVE-2026-24301, CVSS 8.8) — a single crafted link could make consumer Copilot exfiltrate data from connected accounts without confirmation. Server-side patch deployed, no client update needed. Third disclosed Copilot vuln in 8 months. The attack surface is expanding. Purview DLP for external web search is now GA — enable it. Audit SharePoint permissions. Set up monthly Copilot security reviews.

    Post summary

    CVE-2026-24301, a data exfiltration vulnerability via crafted link, has been patched server‑side with no client update needed.

    1000073
    1.6K followersView on X
  • Ai Daily Dose@Aidailydose2
    Patch

    Microsoft patched a serious one-click Copilot vulnerability (CVE-2026-24301, “CoSnitch”). It could silently exfiltrate Gmail, Drive, and other connected data. Another reminder that AI assistants with tool access need ironclad security.

    Post summary

    Microsoft has released a patch for CVE‑2026‑24301, a one‑click Copilot vulnerability that could exfiltrate Google data, highlighting the importance of securing AI assistants with tool access.

    1000030
    214 followersView on X
  • IryoITMemo 医療ITメモ@iryoitmemo
    Disclosure

    Microsoft Copilot Personalに脆弱性、連携アプリからワンクリックでデータを流出させる恐れ(CVE-2026-24301) https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47254/

    Post summary

    The text announces a vulnerability in Microsoft Copilot Personal (CVE‑2026‑24301) that could lead to one‑click data leakage via integrated apps, but it does not provide a PoC, exploit, active exploitation evidence, or a fix.

    1000091
    303 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftcopilot---

Explore more