Mark RadarMARK RADAR
About
EN
Sign in

Microsoft Patches Copilot Flaw That Could Leak Gmail, Cloud Data

1 reports · First detected 2026-08-19 · Last active 2026-08-19

A vulnerability dubbed CoSnitch affected the consumer version of Microsoft Copilot and the permissions linking the AI assistant to services such as Gmail and cloud storage. The flaw was significant because Copilot can access emails and files with a user’s authorization, potentially turning productivity integrations into a channel for stealing sensitive information across connected services.

Security researchers said attackers could lure a user into clicking a specially crafted link that caused Copilot to execute malicious instructions automatically. Those commands could read data from connected Gmail and cloud-drive accounts and transmit it externally. The researchers also found that hostile instructions could persist in the AI’s memory, extending the risk beyond the initial interaction. Microsoft has released an update addressing the vulnerability.

All Coverage

1 original reports

The Backstory

The history behind this event
New Microsoft 365 Copilot Flaw Can Leak Sensitive Data2026-06-18 · 1 reports · similarity 0.84

Microsoft 365 Copilot can search and organize information across corporate documents, emails and collaboration content. If its permissions or query mechanisms are abused, controlled internal data could be exfiltrated. Cybersecurity firm Varonis named the malicious-link attack SearchLeak, highlighting a new data-leak risk arising from enterprise adoption of generative AI.

Varonis disclosed that attackers could lure users into clicking a specially crafted URL, causing Microsoft 365 Copilot to search for sensitive data accessible to those users and exfiltrate the results. Microsoft confirmed the vulnerability as CVE-2026-42824 and said it was fixed in its June 2026 security update. Companies should ensure the update has been deployed.

Major Microsoft Copilot Cowork Flaw Lets Prompt Injection Leak Corporate Secrets2026-05-26 · 1 reports · similarity 0.86

Microsoft 365 Copilot Cowork is an AI agent that can handle enterprise workflows on users’ behalf and access internal data in SharePoint, OneDrive and other services. Because the agent can invoke tools and send messages autonomously, a prompt injection that bypasses permission boundaries could expose not only chat content but also corporate secrets and undermine cloud-file governance.

Cybersecurity firm PromptArmor recently disclosed that attackers could hide malicious instructions in skill files, prompting Copilot Cowork to automatically run a workflow that sends a message to the user and redirects sensitive-file download links to an attacker-controlled server. The number of affected companies, financial losses and exact public disclosure date have not been revealed. The key risk is that data can be exfiltrated without the user’s knowledge.

Microsoft 365 Copilot Bug Reportedly Exposed Confidential Corporate Emails in Summaries2026-02-23 · 1 reports · similarity 0.85

Microsoft 365 Copilot can integrate Outlook emails and use generative AI to produce summaries. Companies typically use data loss prevention (DLP) policies to restrict access to sensitive information. The bug allowed Copilot to bypass existing controls, highlighting the risk that AI assistants could increase the exposure of confidential emails.

The latest disclosure showed that Copilot had accessed sent-message backups and drafts marked as sensitive in Outlook and incorporated their contents into summaries. Microsoft said it completed a fix in early February and that the issue affected only a small number of Outlook desktop users. It did not disclose the exact number of users or identify the companies affected.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)