Validated Research Published: Aug 25, 2026

CoSnitch Combined Copilot Autorun Exfiltration with a Separate Memory-Poisoning Path

CoSnitch covered two independent Copilot attacks. A crafted copilot.microsoft.com link combined ?q= with an undocumented autorun=1 parameter, causing an authenticated session to run an embedded prompt without confirmation and send connected data through URL fetches. Separately, hidden instructions in a webpage summarized by Copilot invoked memory.add and persisted in long-term memory. Microsoft fixed CVE-2026-24301 on August 18.

Prompt InjectionData ExfiltrationModel PoisoningSink EnforcementAI Copilots
9 applicable AIDEFEND defenses
Source: CoSnitch: One Click to Leak Your Secrets or Poison Copilot's Memory 
Author: Lior Adar (Varonis Threat Labs)
Original article: Aug 18, 2026

Threat Analysis

  • The autorun branch needed one user click. The victim opened a legitimate copilot.microsoft.com URL containing an attacker prompt in ?q= and the undocumented autorun=1 switch. The existing authenticated browser session supplied the victim context.
  • The prompt ran without a new confirmation. It instructed Copilot to retrieve information from connected Gmail, Drive, Calendar, and chat history, encode selected values into a URL, and use Copilot's own fetch capability to send the request.
  • The memory branch began in a different workflow. A user asked Copilot to summarize an attacker-controlled webpage. Hidden page text then told the system to call memory.add; this path did not depend on the crafted autorun link.
  • The poisoned record became future prompt context. Copilot could recall the attacker instruction during later conversations. Varonis reports that password changes, session revocation, and device re-registration did not remove the memory; it remained until explicitly deleted.
  • Product naming needs precision. Varonis describes the tested experience as Microsoft Copilot Personal, while Microsoft's formal vulnerability record identifies the affected service as Copilot Web. This brief uses the formal product name and preserves the research wording as an alias.
  • The vendor fixed the reported vulnerability. Microsoft patched CVE-2026-24301 on August 18, 2026. NVD lists CVSS 8.8, required user interaction, and no known exploitation; the durable lesson is to govern both automatic prompt execution and memory writes as security decisions.

Applicable AIDEFEND Defenses (9)

AID-H-018.003
High-Impact Independent Validation & Approval Gate
Very High
A link click and an existing login cannot approve an embedded task. Before connected-data access or external fetches, require a fresh decision bound to the exact prompt, connectors, data classes, destination, and intended action. This directly breaks the autorun branch.
AID-H-018.005
Value-Level Capability Metadata & Data Flow Sink Enforcement
Very High
Tag values from Gmail, Drive, Calendar, and conversation history as sensitive, preserve that status through encoding, and block them from attacker-selected URL parameters. This prevents the exfiltration result even if the prompt and fetch tool both execute.
AID-I-004.004
Transactional Promotion Gates (Quarantine -> Trusted)
Very High
Send webpage-derived memory candidates to quarantine and promote them only through an atomic, reviewed transition bound to the exact content digest. Until promotion, the record cannot influence later prompts. This is the strongest direct control for the durable-memory branch.
AID-H-002.002
Inference-Time Prompt & Input Validation
High
The web request contract should reject an external parameter combination that both supplies and automatically executes a prompt. If q remains linkable, its value must be inert until the user reviews and submits it inside the authenticated session.
AID-H-018.004
Intent-Based Dynamic Capability Scoping
High
Generate a short-lived connector and tool scope from a trusted user-visible task. A URL-provided prompt cannot expand the session to unrelated mail, files, calendar entries, chat history, or arbitrary fetch destinations.
AID-D-001.005
Recalled Memory Pre-Rehydration Scanning
High
Rescan each memory record before it is reloaded into a later prompt. Emit a finding bound to the exact stored version when it asserts hidden authority, requests tool use, or conflicts with the current user task. This is detection and policy evidence, not a substitute for write admission.
AID-E-005
Compromised Durable Application Session & Agent State Teardown
High
After confirming poisoning, purge the exact signed conversational-memory records that can reload the instruction, then independently verify zero remaining state in scope. Password and session changes do not satisfy this requirement because they leave durable memory intact.
AID-H-019.002
Secure HTML Rendering & Content Demotion
Medium
Sanitize the summarized page into bounded plain text and retain its untrusted provenance so active HTML cannot cross the rendering boundary and downstream memory policy can still identify the text as untrusted. This constrains ingress but does not by itself authorize or block a memory write.
AID-M-002.004
Trust-Tiered Memory/KB Provenance & Write Eligibility Contract
Medium
Every proposed memory write should record the caller, source, evidence, validator result, namespace, and eligibility decision for the promotion gate. This contract provides the facts needed for enforcement; it does not make hidden webpage text trustworthy by itself.

What Defenders Should Do Now

  • Verify Microsoft's August 18 fix in the consumer Copilot web surface. Test crafted q and autorun combinations in an isolated account and confirm that no prompt runs before explicit review.
  • List every connector and outbound fetch capability available to Copilot. Require fresh action-specific approval before a prompt can read connected data or contact a model-selected destination.
  • Apply value-aware sink tests to encoded, concatenated, transformed, and URL-embedded Gmail, Drive, Calendar, and chat-history values.
  • Record memory writes as security-relevant events with source, caller, content digest, validator result, namespace, and approval. Quarantine webpage-derived candidates by default.
  • Rescan memory on every recall and test whether hidden authority claims can survive paraphrasing or storage normalization.
  • Create a response runbook that deletes the exact poisoned records and verifies no remaining durable state. Password rotation, session revocation, and device re-registration must not be used as evidence that memory was removed.

Conclusion

CoSnitch exposed two different ways for ambient browser context to inherit Copilot authority. The autorun path turned a link into an authenticated task; the memory path turned untrusted webpage text into durable instructions for future sessions.

AIDEFEND  places AID-H-018.003 and AID-H-018.005 at the immediate action and data-egress boundaries. For persistence, AID-M-002.004 defines which memory writes are eligible, AID-I-004.004 keeps untrusted records quarantined, and AID-E-005 removes the exact durable state after compromise. The two branches need separate tests and separate closure evidence.