Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Summary
Microsoft has patched a critical vulnerability in its personal Copilot AI assistant, nearly eight months after being notified. The "CoSnitch" vulnerability allowed attackers to exfiltrate data by exploiting an LLM's inability to distinguish queries from instructions and could lead to persistent memory poisoning. This is the third Copilot bug reported by Varonis this year, following Reprompt and SearchLeak, all sharing a similar exploit pattern.
IFF Assessment
This vulnerability allowed for data exfiltration and persistent memory poisoning, posing a significant risk to users and their data.
Severity
Defender Context
This article highlights the ongoing risks associated with AI assistants and LLMs, specifically prompt injection attacks that can lead to data exfiltration and persistent compromise. Defenders should be aware of such vulnerabilities in AI-powered tools and emphasize secure configurations and user education against suspicious links.