Microsoft Patches Critical One-Click Copilot Vulnerability

3h ago·0:00 listen·Source: Computerworld

Summary

Microsoft has issued a patch for a critical vulnerability in the personal version of its AI assistant, Copilot. The flaw, named CoSnitch by its discoverer Varonis, allows data to be taken from businesses without obvious alerts. What's interesting is that this fix comes almost eight months after Microsoft first learned of the issue. CoSnitch works because the AI cannot tell the difference between data in a query and an instruction. It could be exploited with just one click on a legitimate-looking link. Varonis identified this as the third Copilot bug reported to Microsoft this year. They include Reprompt, which bypassed guardrails, and SearchLeak, which could turn Microsoft 365 Copilot Enterprise into a "silent exfiltration tool." The CoSnitch flaw itself was found when Copilot essentially revealed its own vulnerability. Researchers prompted Copilot to explain why auto-execution was impossible, and the AI inadvertently disclosed an undocumented URL parameter, allowing the attack to be built. Microsoft confirms customers are now protected and no action is needed. This matters because it highlights ongoing security challenges with AI systems.

Read the full article on Computerworld

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening