‘CoSnitch’ Attack Tricked Copilot into Mapping Out Architecture

Threat actors have discovered a novel way to trick AI-powered chatbots into revealing sensitive information about their own architecture. Researchers at Varonis Threat Labs found that by manipulating Microsoft Copilot’s natural language processing capabilities, they could get the chatbot to reveal details about its internal workings and even execute malicious code.

The technique, dubbed “CoSnitch,” allows threat actors to map out a chatbot’s architecture and identify potential attack paths. By asking seemingly innocuous questions, researchers were able to extract technical details about Copilot’s behavior, including how prompts could be executed without direct user interaction. This information was then used to build a specially crafted link that could bypass Microsoft’s guardrails and execute malicious code within the chatbot.

The “CoSnitch” attack works by manipulating Copilot into revealing sensitive information through its own responses. By asking questions about URL structures, deep links, and prompt handling, researchers were able to extract technical details about Copilot’s behavior. This information was then used to build a specially crafted link that could bypass Microsoft’s guardrails and execute malicious code within the chatbot.

The attack has significant implications for AI-powered chatbots like Copilot, which are increasingly being used in personal and enterprise settings. By exploiting these vulnerabilities, threat actors can gain access to sensitive information, inject disinformation, and even take control of connected services. Varonis reported CoSnitch to Microsoft in December 2025, and patches were shipped on August 18 following a coordinated disclosure process.

Microsoft has confirmed that no customer action is required to address the issue, as enterprise customers are unaffected by CoSnitch (it only affected Copilot Personal). However, this incident highlights the need for greater scrutiny of AI-powered chatbots and their potential vulnerabilities. Even though the issue has been addressed, researchers warn that meta-hacking remains a concern going forward.

The CoSnitch attack is a stark reminder of the importance of security in AI development. As AI assistants become increasingly integrated into our daily lives, it’s essential to prioritize robust security measures to prevent similar attacks from occurring in the future. In the meantime, users should remain vigilant when interacting with AI-powered chatbots and be aware of potential vulnerabilities.

To mitigate this risk, users can take a few simple precautions: always verify links before clicking on them, use strong passwords for connected services, and keep software up-to-date. Additionally, AI developers must prioritize robust security measures to prevent similar attacks from occurring in the future. By doing so, we can ensure that AI-powered chatbots continue to provide value while minimizing potential risks.


Source: Dark Reading — 2026-08-18