Microsoft has shipped a patch for CVE-2026-24301, a critical vulnerability in its Copilot AI assistant that was dubbed 'CoSnitch' by Varonis Threat Labs. The flaw, reported to Microsoft in December 2024, took roughly eight months to fully remediate.

The attack chain was sophisticated: it exploited an undocumented URL parameter in combination with Copilot's built-in URL fetch capability and persistent memory poisoning. A single malicious link could auto-execute prompts that exfiltrate connected Gmail, Drive, and Calendar data — without any user click or confirmation.

The vulnerability fell into a growing category of AI-specific security issues: prompt injection attacks that leverage the data access capabilities built into AI assistants. Unlike traditional phishing, which tricks users into entering credentials, CoSnitch abused the trust relationship between Copilot and its connected services.

Varonis disclosed that the attack worked across Copilot's enterprise deployment, potentially exposing corporate emails, documents, and scheduling data. Microsoft mitigated the issue server-side before shipping the client-side patch.

The incident highlights the security risks of AI assistants that have deep integration with productivity suites. As organizations connect Copilot, ChatGPT, and similar tools to email, calendar, and file storage systems, the attack surface expands dramatically — and vulnerabilities in these AI layers can bypass traditional security controls.