**Critical Vulnerability Exposed: CoSnitch Attack Tricks Copilot into Mapping Out Architecture**
A sophisticated threat actor can trick a Microsoft Copilot instance into revealing its own security weaknesses, paving the way for a novel prompt injection attack. This is according to new research published by Varonis Threat Labs, which discovered a “meta-hacking” technique that manipulates the AI service into exposing critical details about its architecture.
The CoSnitch attack works by socially engineering a Copilot Personal instance to reveal a chain of vulnerabilities, including memory poisoning, automatic prompt execution through a specially crafted URL, and data exfiltration. This was achieved by asking Copilot seemingly innocuous follow-up questions about URL structures, deep links, and prompt handling, which ultimately led to the mapping out of portions of the AI’s architecture.
Researchers at Varonis began by asking Copilot how prompts could be executed without direct user interaction. The chatbot repeatedly explained that prompts require user intent, but in doing so divulged technical details about its own behavior. By posing a series of follow-up questions, researchers gradually built up a picture of Copilot’s architecture and identified a potential attack path.
The CoSnitch attack is notable for its use of meta-hacking, which involves exploiting the AI itself to reveal its weaknesses. This technique has significant implications, as it highlights the vulnerability of even well-designed AI systems to manipulation. As Varonis researcher Lior Adar noted, “Even though this issue has been addressed by Microsoft, meta-hacking remains the most concerning element of the attack chain going forward.”
Microsoft has since patched the vulnerability and assigned CVE-2026-24301 to the issue, an information disclosure vulnerability related to Copilot. The company’s spokesperson assured that no customer action is required, as enterprise customers are unaffected by CoSnitch.
However, the CoSnitch attack serves as a reminder of the ongoing threat posed by prompt injection attacks. As Adar noted, “Every AI Assistant is a Privileged Insider,” and even seemingly innocuous interactions can be exploited to reveal sensitive information or execute malicious actions.
**What does this mean for you?**
While the CoSnitch attack was limited in its impact, it highlights the importance of ongoing vigilance when interacting with AI-powered services. As AI becomes increasingly ubiquitous, it’s essential to remember that even well-designed systems can be vulnerable to manipulation.
To protect yourself from similar attacks, it’s crucial to remain aware of the potential risks associated with using AI assistants and to follow best practices for secure interaction. This includes being cautious when sharing sensitive information or clicking on links, especially those sent by unknown parties.
In light of the CoSnitch attack, it’s also essential to stay informed about emerging threats and vulnerabilities in AI systems. By staying ahead of the curve, you can better protect yourself from the evolving landscape of cyber threats.
Source: Dark Reading — 2026-08-18