A critical vulnerability in Copilot allowed user data to be stolen
A critical vulnerability was discovered in Microsoft Copilot that allowed attackers to access users' personal data through a specially crafted link. The issue has already been resolved, and there is no evidence that it was exploited. Users are advised to check and, if necessary, clear Copilot's saved memory.
Crius
Research on Microsoft Copilot Vulnerability
Vulnerability Discovery
Experts identified a vulnerability in the Microsoft Copilot AI assistant by submitting a series of queries about why certain commands could not be executed. During the analysis, Copilot revealed information about an undocumented address bar parameter and the security measures implemented around it. Using this data, the researchers were able to reconstruct the correct address, which allowed them to reproduce the vulnerability.
Fix and Risk Assessment
The vulnerability was patched by Microsoft on August 18. The issue was assigned the identifier CVE-2026-24301 and received a critical CVSS score of 8.8 out of 10. CVSS is used for standardized assessment of vulnerability severity in the industry. The vulnerability affected the consumer version of Copilot, which was recently merged with the subscription tier.
Attack Mechanism
To exploit the vulnerability, only a single link was needed. When a user clicked the link, Copilot would launch within their already authenticated session. An additional parameter in the address allowed an attacker’s command to be executed without any confirmation or the need to press a send button. After this, Copilot would search connected email, calendar, and cloud storage, collect the found information, and send it to a specified web address. For network security tools, this activity appeared as a regular request to a page that Copilot was supposed to summarize.
During testing, it was possible to obtain passwords sent via email, meeting details, file names from cloud storage, and the history of previous chats.
Long-Term Memory Features
The greatest risk was posed by Copilot’s long-term memory. The assistant retains information beyond a single conversation. When summarizing a malicious web page, hidden instructions would be stored in memory, while the user would see only a normal summary. This information persisted even after a password change, logging out of all sessions, and re-registering the device—actions typically taken when unauthorized access is suspected.
Verification and Recommendations
Microsoft has fixed the vulnerability on its servers, so no additional updates are required from users. There have been no signs of this attack being used in the wild. The issue was reported in December 2025, and the fix was released eight months later.
Users can check their saved Copilot memory at copilot.microsoft.com via the account button in the sidebar. All entries are displayed there and can be deleted individually or all at once. Unusual records are usually noticeable at first glance.
Vulnerability History
CoSnitch became the third Copilot vulnerability discovered this year. The previous two were exploited in a similar way—through a single click on an apparently harmless external link.
