Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it

Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this…

Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it

Microsoft finally patched a critical vulnerability in its AI assistant, Copilot, nearly eight months after discovering it. The flaw, known as CoSnitch, allowed attackers to execute malicious prompts automatically through a single-click link, potentially exfiltrating sensitive data and persisting in the victim's memory. Varonis discovered the CoSnitch bug, which involved three different Copilot vulnerabilities, including automatic prompt execution, data exfiltration, and persistent memory poisoning.

Despite Microsoft's claim that enterprise customers were not affected, analysts stressed that the flaw could still impact enterprise systems through personal Copilot accounts. The patch was completed on February 1, but Microsoft's timeline for addressing the vulnerability was fragmented. The discovery of CoSnitch was particularly concerning as it revealed a previously unknown weakness in Copilot's architecture, prompting Microsoft to disclose the vulnerability and issue a fix.

However, the financial incentives for AI companies like Microsoft may make it challenging to fully resolve such vulnerabilities, as the fixes could potentially compromise the product's value proposition.

Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at computerworld.com →

More in Tech

More from Wednesday 19 August →