Breaking Lab srl
When your AI assistant becomes a data leak
AI assistants are useful partly because they connect to everything — your email, your calendar, your files. That same connectedness is exactly what makes them dangerous when something goes wrong. And something has gone wrong with Microsoft Copilot Personal.
Security researchers at Varonis Threat Labs found three vulnerabilities in the consumer version of Copilot, the AI assistant built into Microsoft’s products. Together, the flaws — nicknamed CoSnitch — mean that if you click a single malicious link, an attacker could silently read data from any app your Copilot account is connected to, without you noticing anything unusual.
What the flaws actually do
The attack works by exploiting how Copilot handles certain web addresses. One of the vulnerabilities uses an undocumented URL parameter — a hidden setting in a web link that changes how the software behaves — that Copilot itself exposed to researchers. By crafting a link that triggers this parameter in a specific way, an attacker can redirect Copilot’s internal requests to a server they control.
That technique is called Server-Side Request Forgery, or SSRF — essentially tricking a trusted system into fetching data on an attacker’s behalf. Because Copilot already has permission to read your connected apps, the assistant does the data collection for the attacker. No password is stolen. No warning appears. The assistant just quietly hands over what it can access.
The researchers note that this requires the victim to click a crafted link — it does not happen automatically. But in practice, that is a low bar. Phishing emails, fake support messages, and malicious links in search results are common delivery methods, and most people cannot tell a dangerous link from a safe one at a glance.
Why AI assistants are an attractive target
Traditional attacks usually target one app at a time. Compromising a calendar app gets you calendar data. Compromising email gets you email. But an AI assistant that bridges many apps is a single point that, if exploited, gives access to all of them at once. The more useful you make your Copilot by connecting it to more services, the more valuable it becomes as an attack surface.
Microsoft was notified of the vulnerabilities and has since patched them. There is no evidence they were exploited in the wild before the fix. Varonis waited until the patches were available before publishing its findings, which is standard responsible disclosure practice.
What this signals going forward
As AI assistants gain deeper access to personal and work data, they will keep attracting this kind of research — and this kind of attacker interest. The CoSnitch findings are a reminder that convenience and security often pull in opposite directions, and that connecting powerful tools to sensitive data always raises the stakes when something breaks.







