Copilot tricked into revealing a one-click data theft flaw
Microsoft Copilot Personal exposed an undocumented URL mechanism that researchers used to run attacker-supplied prompts without user confirmation. The CoSnitch attack could turn a single phishing link, QR code, or message into a way to search connected mail and files, exfiltrate sensitive data, and alter Copilot’s stored memory.
Source
👉@sysadminoff
https://4sysops.com/archives/copilot-tricked-into-revealing-a-one-click-data-theft-flaw/
Post #19451
65
