Microsoft Copilot Personal flaw let crafted links auto-run prompts to exfiltrate data and poison the assistant’s memory

Researchers say Microsoft Copilot Personal could be tricked into explaining and enabling an attack against itself, letting a malicious link make the assistant send data to an external server and alter its persistent memory. Varonis Threat Labs reported the issue in December 2025 and says Microsoft planned a patch and CVE on August 18, 2026. The attack used Copilot web parameters including q and an undocumented autorun=1 value to auto-execute a supplied prompt under specific session conditions, turning prompt injection into a no-click or near-no-click data-exfiltration path.
Why it matters: People and organizations using Copilot links could be exposed to phishing-style attacks that silently make the assistant leak data or retain poisoned instructions. Users should apply Microsoft's fix as soon as available and treat unsolicited Copilot URLs, QR codes, and messages as suspicious.

Sources

Copilot tricked into telling reseachers how to hack itself
2026.08.18 100% relevant
This article appears to be the first concrete report of the CoSnitch Copilot Personal vulnerability, including the attack chain, affected product, and Microsoft's planned patch/CVE.
← Back to all stories