Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Summary

Varonis Threat Labs has revealed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch. These flaws could permit a single click on a malicious link to silently extract data from connected applications and other information accessible within a user's Copilot session.

IFF Assessment

FOE

These vulnerabilities allow for unauthorized data exfiltration, which is detrimental to defenders.

Severity

8.0 High (AI Estimated)

The vulnerabilities allow for silent data exfiltration with a single click, indicating a high impact and exploitability.

Defender Context

This discovery highlights the importance of scrutinizing how AI assistants integrate with and access data from other applications. Defenders should be aware of potential indirect attack vectors facilitated by these integrations and encourage users to exercise caution with links shared within AI assistant contexts.

Read Full Story →