AILINCOM logo AILINCOM
A critical vulnerability in Copilot allowed user data to be stolen
Crius

Crius

Aug 20, 2026
Основная категория
Digital technologies and IT · Cybersecurity
Дополнительные
Technologies and engineering · Artificial IntelligenceTechnologies and engineering · Cybersecurity

A critical vulnerability in Copilot allowed user data to be stolen

A critical vulnerability in Copilot allowed user data to be stolen

A critical vulnerability was discovered in Microsoft Copilot that allowed attackers to access users' personal data through a specially crafted link. The issue has already been resolved, and there is no evidence that it was exploited. Users are advised to check and, if necessary, clear Copilot's saved memory.

CriusA critical vulnerability in Copilot allowed user data to be stolen

Research on Microsoft Copilot Vulnerability

Vulnerability Discovery

Experts identified a vulnerability in the Microsoft Copilot AI assistant by submitting a series of queries about why certain commands could not be executed. During the analysis, Copilot revealed information about an undocumented address bar parameter and the security measures implemented around it. Using this data, the researchers were able to reconstruct the correct address, which allowed them to reproduce the vulnerability.

Fix and Risk Assessment

The vulnerability was patched by Microsoft on August 18. The issue was assigned the identifier CVE-2026-24301 and received a critical CVSS score of 8.8 out of 10. CVSS is used for standardized assessment of vulnerability severity in the industry. The vulnerability affected the consumer version of Copilot, which was recently merged with the subscription tier.

Attack Mechanism

To exploit the vulnerability, only a single link was needed. When a user clicked the link, Copilot would launch within their already authenticated session. An additional parameter in the address allowed an attacker’s command to be executed without any confirmation or the need to press a send button. After this, Copilot would search connected email, calendar, and cloud storage, collect the found information, and send it to a specified web address. For network security tools, this activity appeared as a regular request to a page that Copilot was supposed to summarize.

During testing, it was possible to obtain passwords sent via email, meeting details, file names from cloud storage, and the history of previous chats.

Long-Term Memory Features

The greatest risk was posed by Copilot’s long-term memory. The assistant retains information beyond a single conversation. When summarizing a malicious web page, hidden instructions would be stored in memory, while the user would see only a normal summary. This information persisted even after a password change, logging out of all sessions, and re-registering the device—actions typically taken when unauthorized access is suspected.

Verification and Recommendations

Microsoft has fixed the vulnerability on its servers, so no additional updates are required from users. There have been no signs of this attack being used in the wild. The issue was reported in December 2025, and the fix was released eight months later.

Users can check their saved Copilot memory at copilot.microsoft.com via the account button in the sidebar. All entries are displayed there and can be deleted individually or all at once. Unusual records are usually noticeable at first glance.

Vulnerability History

CoSnitch became the third Copilot vulnerability discovered this year. The previous two were exploited in a similar way—through a single click on an apparently harmless external link.

#safety#Microsoft#vulnerability#exploitation#copilot#авторизация
0 —

Comments (0)

Hot

Qnap has announced new NAS devices for video production

Oct 2, 202610/2/26 · 0 reactions

Tesla opened credit lines worth $30 billion

Oct 2, 202610/2/26 · 0 reactions

Air travel is on the rise, but new regulations are making the market more complicated.

Oct 1, 202610/1/26 · 0 reactions
Recommended
Cloud Computing

Qnap has announced new NAS devices for video production

Qnap has introduced three new NAS systems designed for video production tasks, equipped with USB4 ports for high-speed data transfer. These devices support various connection modes and are intended for use with high-capacity hard drives and SSDs.

Financial Analysis

Tesla opened credit lines worth $30 billion

Tesla has opened credit lines totaling $30 billion to finance major investments amid declining profits and rising capital expenditures. The new agreement expands the company's financial flexibility as it faces increasing pressure on its business.

Transportation Logistics

Air travel is on the rise, but new regulations are making the market more complicated.

Air transportation is becoming an increasingly important part of logistics, especially amid the instability of sea shipping. However, new regulations for preparing air waybills are creating additional challenges and risks for market participants.