{
  "id": 1851409,
  "title": "Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it",
  "url": "https://urgent.news/2026/08/19/microsoft-finally-patches-critical-one-click-copilot-vulnerability",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T02:23:18.000Z",
  "source": {
    "name": "Computerworld",
    "slug": "computerworld",
    "url": "https://www.computerworld.com/article/4211325/microsoft-finally-patches-critical-one-click-copilot-vulnerability-more-than-eight-months-after-learning-of-it.html"
  },
  "original_language": "en",
  "account": "Microsoft finally patched a critical vulnerability in its AI assistant, Copilot, nearly eight months after discovering it. The flaw, known as CoSnitch, allowed attackers to execute malicious prompts automatically through a single-click link, potentially exfiltrating sensitive data and persisting in the victim's memory. Varonis discovered the CoSnitch bug, which involved three different Copilot vulnerabilities, including automatic prompt execution, data exfiltration, and persistent memory poisoning. Despite Microsoft's claim that enterprise customers were not affected, analysts stressed that the flaw could still impact enterprise systems through personal Copilot accounts. The patch was completed on February 1, but Microsoft's timeline for addressing the vulnerability was fragmented. The discovery of CoSnitch was particularly concerning as it revealed a previously unknown weakness in Copilot's architecture, prompting Microsoft to disclose the vulnerability and issue a fix. However, the financial incentives for AI companies like Microsoft may make it challenging to fully resolve such vulnerabilities, as the fixes could potentially compromise the product's value proposition.",
  "summary": "Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction. The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}