Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Brief
Almost eight months after confirming a critical security vulnerability within the personal version of its AI assistant, Copilot, Microsoft on Tuesday issued a patch to close the hole, which relies on an LLM’s inability to distinguish the data in a query from an instruction.
The CoSnitch hole was discovered by Varonis, and marked the third Copilot bug that Varonis has reported to Microsoft this year, following Reprompt, which bypassed Copilot guardrails by repeating queries, and SearchLeak, which Varonis said turned Microsoft 365 Copilot Enterprise into “a silent exfiltration tool. All three share the same exploit pattern: one click on a legitimate-looking link is enough.”
A detailed blog, posted by Varonis on Tuesday, said the hole’s capabilities were significant. CoSnitch relied on an attacker leveraging three different Copilot flaws, Varonis wrote: Automatic prompt execution. “The ?
