{"slug": "researchers-asked-copilot-how-to-hack-it-and-it-explained-its", "title": "Researchers Asked Copilot How to Hack It  -  and It Explained Its", "summary": "Varonis Threat Labs disclosed CoSnitch, a chain of three flaws in Microsoft Copilot Personal tracked as CVE-2026-24301 and rated 8.8 on the CVSS 3.1 scale, which allowed one click on a link to run attacker-controlled prompts and pull data from connected Gmail, Google Drive, Google Calendar, and Copilot's memory. The discovery method, called meta-hacking, involved asking Copilot why automatic prompt execution should be impossible, leading the model to disclose its own architecture. Microsoft shipped a patch on August 18, 2026, about eight months after the December 2025 report, and no exploitation in the wild has been found.", "body_md": "# Researchers Asked Copilot How to Hack It - and It Explained Its\n\nVaronis found a critical flaw in Microsoft Copilot Personal by asking the assistant why the attack should fail. The technique, called meta-hacking, let…\n\nA security team found a critical vulnerability in Microsoft [Copilot](/compare/github-copilot-vs-cursor) and it wasn't by reverse-engineering the code. They just asked the assistant how to break itself.\n\nVaronis Threat Labs disclosed CoSnitch this week, a chain of three flaws in Microsoft Copilot Personal tracked as CVE-2026-24301 and rated 8.8 on the CVSS 3.1 scale. One click on an ordinary-looking link was enough to run attacker-controlled prompts inside a victim's authenticated session and pull data from connected Gmail, Google Drive, Google Calendar, and Copilot's own memory.\n\nBut the discovery method is the part that will be quoted for years.\n\n## Meta-Hacking: Ask, Reframe, and Ask Again\n\nVaronis calls the technique meta-hacking. Researchers repeatedly asked Copilot why automatic prompt execution ought to be impossible. Each time the model refused to help, they reframed the question as a follow-up. The assistant declined to give harmful instructions - and then disclosed its own architecture anyway.\n\nPiece by piece, Copilot explained its URL handling and historical protections in enough detail to expose an undocumented [parameter](/glossary/parameter). The model never crossed its own safety line, yet it handed over exactly the information needed to build an attack against it. That's the structural problem: a model that explains its own [reasoning](/glossary/reasoning) helpfully will, sometimes, explain its own architecture.\n\n## Three Links in the Chain\n\nThe exploit chains three separate weaknesses. First, automatic prompt execution - an undocumented URL parameter fired a prompt with no user interaction, running to completion even if the victim closed the tab immediately. Second, OAuth connector abuse, which let the attacker read full Gmail message bodies rather than just metadata. Third, persistent memory poisoning - a crafted page, once summarized, wrote attacker instructions into Copilot's permanent memory.\n\nThat last one is the most unsettling. Varonis reports the memory write survives password changes, session revocation, and device re-enrollment. It produced no process, no file, no network connection, and no log entry that standard security tooling would flag. It was visible only inside Copilot's own memory interface.\n\n## Eight Months From Report to Patch\n\nThe timeline is the second story. Varonis reported the flaw in December 2025. Microsoft shipped the patch on August 18, 2026 - about eight months later. Varonis found no evidence of exploitation in the wild, and Microsoft says no customer action is required. But eight months is a long time for a single-click, cross-account exfiltration flaw to sit open.\n\nCoSnitch is the third Copilot flaw Varonis has reported this year. Reprompt bypassed [guardrails](/glossary/guardrails) by asking the same question twice. SearchLeak turned Microsoft 365 Copilot Enterprise into a silent exfiltration channel. All three share one pattern: a single click on a legitimate-looking link.\n\n## Why This Generalizes\n\nThe uncomfortable implication is that meta-hacking isn't specific to Microsoft. Every vendor shipping a reasoning-visible assistant now has the same exposure. A model that explains its thought process transparently is a model that can be coaxed into explaining its own safeguards, its own parameters, and its own attack surface.\n\nThe security industry has spent two years hardening models against direct jailbreaks. Meta-hacking is different. It doesn't ask the model to do anything harmful. It asks the model to be helpful and transparent about itself - and that helpfulness is the vulnerability. The fix isn't obvious, because the thing being exploited is the exact transparency the industry has been selling as a feature.\n\n*Sources: Varonis Threat Labs disclosure, August 20, 2026; AI Tools Recap daily briefing, August 20, 2026; Microsoft security advisory for CVE-2026-24301.*\n\nGet AI news in your inbox\n\nDaily digest of what matters in AI.\n\n## Key Terms Explained\n\n[Guardrails](/glossary/guardrails)\n\nSafety measures built into AI systems to prevent harmful, inappropriate, or off-topic outputs.\n\n[Parameter](/glossary/parameter)\n\nA value the model learns during training — specifically, the weights and biases in neural network layers.\n\n[Reasoning](/glossary/reasoning)\n\nThe ability of AI models to draw conclusions, solve problems logically, and work through multi-step challenges.", "url": "https://wpnews.pro/news/researchers-asked-copilot-how-to-hack-it-and-it-explained-its", "canonical_source": "https://www.machinebrief.com/news/cosnitch-copilot-personal-meta-hacking-cve-2026-24301-varonis", "published_at": "2026-08-20 13:04:40+00:00", "updated_at": "2026-08-20 13:13:27.447527+00:00", "lang": "en", "topics": ["ai-safety", "ai-ethics", "ai-products"], "entities": ["Varonis Threat Labs", "Microsoft Copilot Personal", "CoSnitch", "CVE-2026-24301", "Microsoft", "Gmail", "Google Drive", "Google Calendar"], "alternates": {"html": "https://wpnews.pro/news/researchers-asked-copilot-how-to-hack-it-and-it-explained-its", "markdown": "https://wpnews.pro/news/researchers-asked-copilot-how-to-hack-it-and-it-explained-its.md", "text": "https://wpnews.pro/news/researchers-asked-copilot-how-to-hack-it-and-it-explained-its.txt", "jsonld": "https://wpnews.pro/news/researchers-asked-copilot-how-to-hack-it-and-it-explained-its.jsonld"}}