Microsoft Copilot has faced a serious security scare, a major flaw has been found in its system. Researchers found a way to make the AI act without normal user approval. A single click could then put private data at risk.
Microsoft Copilot was tricked into breaking its own rules
The flaw was found by researchers from security firm Varonis. They called the attack chain โCoSnitchโ. Microsoft later tracked the main issue as CVE-2026-24301 and gave it a high severity score of 8.8 out of 10. As reported by Ars Technica, the researchers did not start by breaking into Copilot’s code. Instead, they kept asking the AI questions about its own safety rules. Each answer gave them more clues about how its defences worked. They called this method โmeta-hackingโ.
The strange part was that Microsoft’s AI itself helped reveal the path. At first, the AI refused requests that could run without user approval. But its replies also explained why those requests were blocked. By asking more questions, the researchers slowly learned about the limits of those protections. The researchers eventually found an undocumented input that could bypass the normal need for a user action. This meant a specially made link could cause Copilot to process a hidden request after the victim clicked it.
A simple click could expose private data
The danger became much bigger when Copilot was connected to other apps. The research reportedly showed how an attacker could use a harmful link to start a chain of actions inside Copilot. If the AI had access to connected services, private information could potentially be reached and sent outside.
The risk could include data from services such as Gmail and Google Drive. The researchers also found another issue involving Copilot’s memory. Malicious instructions hidden inside a webpage could be used to change what the AI remembered about a user. This made the problem more worrying than a normal software bug.
A user did not need to type a dangerous command. They only needed to click a link. That link could arrive through an email, message or other online content. The researchers showed that sensitive information such as passwords and other account details of the user or of a business organization could be targeted in their tests.

Microsoft has fixed the flaw in Copilot
Microsoft was informed about the CoSnitch issues in December 2025. The company later made changes to reduce the risk. More fixes were applied in August 2026. The main fix was reportedly made on the server side. This means normal users do not need to install a special update to address this particular issue.
Microsoft said customers are protected and thanked the researchers for reporting the problem. The company also said it continues to improve Copilot’s safety systems. The case also raises a wider question about AI security. Modern assistants can connect to email, files, calendars and other tools. That makes them useful. It can also make a small weakness much more serious. The researchers believe similar methods could affect other AI systems too. Their warning is simple. AI security cannot depend only on rules that tell a model what not to do.
Authorโs Opinion
This incident shows why AI tools need strong safety checks. Copilot was not simply โhackedโ in the usual way. Researchers found a weakness by talking to it. That makes the problem unusual, but also a useful warning for the whole AI industry.
READ MORE: Google to pay $10 million for Spirit Airlines data for AI.
ALSO READ: Meta faces $200bn legal battle over alleged child addiction.
READ NEXT: Tesla to launch Cybercab in Austin as soon as this month.