Security· August 18, 2026 at 01:00 p.m.
Microsoft Copilot Personal Vulnerability Allows Data Exfiltration
Key takeaways
- Varonis Threat Labs discovered a vulnerability in Microsoft Copilot Personal
- The vulnerability allows attackers to exfiltrate sensitive data
- Microsoft is planning to issue a patch and identify the CVE
Researchers from Varonis Threat Labs have discovered a vulnerability in Microsoft's Copilot Personal AI assistant, named 'CoSnitch'. The security flaw allows attackers to exfiltrate sensitive data by manipulating the AI's reasoning engine and tricking it into sending data to an external server. The vulnerability was reported to Microsoft in December 2025, with a planned patch and CVE identification scheduled for release on Tuesday.