Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Summary
Varonis Threat Labs has revealed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch. These flaws could permit a single click on a malicious link to silently extract data from connected applications and other information accessible within a user's Copilot session.
IFF Assessment
These vulnerabilities allow for unauthorized data exfiltration, which is detrimental to defenders.
Severity
The vulnerabilities allow for silent data exfiltration with a single click, indicating a high impact and exploitability.
Defender Context
This discovery highlights the importance of scrutinizing how AI assistants integrate with and access data from other applications. Defenders should be aware of potential indirect attack vectors facilitated by these integrations and encourage users to exercise caution with links shared within AI assistant contexts.