Copilot tricked into telling reseachers how to hack itself
What happened
Varonis researchers manipulated Microsoft Copilot Personal into revealing how to hack itself and exfiltrate data using prompt‑injection and a discovered autorun parameter. The exploit can trigger OAuth connectors (Gmail, Drive, Calendar) and pull chats or files; Microsoft planned a patch and formal CVE disclosure. Operationally, enterprise customers using persistent memory or external connectors should expect configuration guidance and patches and must watch vendor mitigation timelines
Why the category manager should care
Treat deployed AI assistants and their connectors as high‑risk integrations that require inventory, explicit disable controls, patch commitments, and connector‑specific SLAs
Key facts
- Vulnerability disclosed by Varonis Threat Labs and named 'CoSnitch'
- Exploit uses an 'autorun=1' prompt parameter delivered via crafted URL to trigger connector a
- Microsoft planned to issue a patch and formally identify a CVE