Microsoft Patches Critical Copilot Vulnerability, Eight Months After Discovery
Microsoft has finally patched a critical security vulnerability in its personal version of AI assistant Copilot. The CoSnitch hole was discovered by Varonis and relies on an LLM's inability to distinguish between data in a query and instructions.
The vulnerability, which can lead to data exfiltration and memory poisoning, was first reported by Varonis on December 31 but only fully patched on Tuesday, eight months later. In that time, Microsoft had already patched one element of the hole on February 1, but it wasn't until now that all three flaws were fixed.
Varonis' researchers used a sophisticated method to trick Copilot into revealing its own flaws. By reframing every refusal as a follow-up question and each answer narrowing the attack surface further, they managed to get Copilot to disclose an undocumented URL parameter.