Copilot Personal Link Hid a One-Click Exfil Path

Varonis said Microsoft patched Copilot Personal on August 18 after its CoSnitch research uncovered CVE-2026-24301, a flaw at copilot.microsoft.com that could turn a crafted link into a one-click data exfiltration path. The firm says it found the hidden behavior by questioning Copilot until the assistant disclosed an undocumented `autorun=1` parameter. The trick was to pair that switch with Copilot’s normal `q` query field, which could prefill the prompt and make it run as soon as the victim opened the URL. In Varonis’ tests, the resulting prompt could read data from services the user had already connected and send it out through Copilot’s own URL-fetching behavior, so the risk lived inside an authenticated assistant session, not just in the browser. Ars Technica frames the issue as Microsoft 365 Copilot Enterprise, while The Hacker News says the disclosed CVE is for Copilot Personal; either way, the exposure sits at the trust boundary where a chat assistant can both explain its guardrails and be driven by them. If Copilot-like tools can see connected data, a click on a trusted assistant link can become the moment that data leaves the session.

Part of the PlainSec briefing for 2026-08-18

Every edition of this story: Copilot Personal Link Hid a One-Click Exfil Path

Sources