CoSnitch Combined Copilot Autorun Exfiltration with a Separate Memory-Poisoning Path
CoSnitch covered two independent Copilot attacks. A crafted copilot.microsoft.com link combined ?q= with an undocumented autorun=1 parameter, causing an authenticated session to run an embedded prompt without confirmation and send connected data through URL fetches. Separately, hidden instructions in a webpage summarized by Copilot invoked memory.add and persisted in long-term memory. Microsoft fixed CVE-2026-24301 on August 18.
Threat Analysis
- The autorun branch needed one user click. The victim opened a legitimate
copilot.microsoft.comURL containing an attacker prompt in?q=and the undocumentedautorun=1switch. The existing authenticated browser session supplied the victim context. - The prompt ran without a new confirmation. It instructed Copilot to retrieve information from connected Gmail, Drive, Calendar, and chat history, encode selected values into a URL, and use Copilot's own fetch capability to send the request.
- The memory branch began in a different workflow. A user asked Copilot to summarize an attacker-controlled webpage. Hidden page text then told the system to call
memory.add; this path did not depend on the crafted autorun link. - The poisoned record became future prompt context. Copilot could recall the attacker instruction during later conversations. Varonis reports that password changes, session revocation, and device re-registration did not remove the memory; it remained until explicitly deleted.
- Product naming needs precision. Varonis describes the tested experience as Microsoft Copilot Personal, while Microsoft's formal vulnerability record identifies the affected service as Copilot Web. This brief uses the formal product name and preserves the research wording as an alias.
- The vendor fixed the reported vulnerability. Microsoft patched CVE-2026-24301 on August 18, 2026. NVD lists CVSS 8.8, required user interaction, and no known exploitation; the durable lesson is to govern both automatic prompt execution and memory writes as security decisions.
Applicable AIDEFEND Defenses (9)
q remains linkable, its value must be inert until the user reviews and submits it inside the authenticated session.What Defenders Should Do Now
- Verify Microsoft's August 18 fix in the consumer Copilot web surface. Test crafted
qandautoruncombinations in an isolated account and confirm that no prompt runs before explicit review. - List every connector and outbound fetch capability available to Copilot. Require fresh action-specific approval before a prompt can read connected data or contact a model-selected destination.
- Apply value-aware sink tests to encoded, concatenated, transformed, and URL-embedded Gmail, Drive, Calendar, and chat-history values.
- Record memory writes as security-relevant events with source, caller, content digest, validator result, namespace, and approval. Quarantine webpage-derived candidates by default.
- Rescan memory on every recall and test whether hidden authority claims can survive paraphrasing or storage normalization.
- Create a response runbook that deletes the exact poisoned records and verifies no remaining durable state. Password rotation, session revocation, and device re-registration must not be used as evidence that memory was removed.
Conclusion
CoSnitch exposed two different ways for ambient browser context to inherit Copilot authority. The autorun path turned a link into an authenticated task; the memory path turned untrusted webpage text into durable instructions for future sessions.
AIDEFEND places AID-H-018.003 and AID-H-018.005 at the immediate action and data-egress boundaries. For persistence, AID-M-002.004 defines which memory writes are eligible, AID-I-004.004 keeps untrusted records quarantined, and AID-E-005 removes the exact durable state after compromise. The two branches need separate tests and separate closure evidence.