CoSnitch didn't hack Copilot's model. It hacked everything Copilot was allowed to touch.
Eight months. That's how long Microsoft sat on a bug that let a single click drain someone's Gmail, Google Drive, Calendar, and Copilot's own memory store, disguised as routine traffic.
Varonis Threat Labs reported it in December 2025. Microsoft patched it on August 18, 2026. The bug has a name now: CoSnitch, CVE-2026-24301, CVSS 8.8.
Here's the mechanic, stripped down. Copilot Personal had an undocumented URL parameter, autorun=1, that paired with its query function to execute an embedded prompt the moment a page loaded. No typing, no confirmation. An attacker sends a link, the victim clicks it once, and Copilot starts acting inside that victim's authenticated session. It pulls message bodies and sender metadata from connected mail, calendar entries, file names from Drive, prior chat history, and the saved rules sitting in its memory store. Then it uses its own built-in URL-fetch feature to ship all of that to a server the attacker controls, and the traffic looks like the assistant just fetching a page, which is exactly what it's supposed to do.
The part that should worry people more than the exfiltration path is the second one. A crafted webpage, once summarized by Copilot, could write attacker instructions straight into the victim's permanent memory. That write doesn't touch a file, doesn't open a connection, doesn't throw an error. It shows up in the memory interface looking like any other saved preference. Every log a security team would normally check comes back clean.
I want to be careful here, because the easy read is "Microsoft shipped sloppy code." Sure, an undocumented parameter that auto-executes prompts is a real defect, and eight months to patch a CVSS 8.8 is slow by any standard. But that framing misses the actual lesson, which is architectural, not a QA failure.
You gave an assistant persistent memory. You connected it to mail, calendar, and cloud storage. You gave it a tool that can reach out to arbitrary URLs on your behalf. Each of those is a reasonable feature in isolation. Put all three in the same trust boundary and you've built a confused deputy with your inbox as the payload. The model doesn't need to be tricked into doing something clever. It just needs to follow an instruction that happens to be sitting on a webpage it was asked to summarize, using permissions it already had.
This is the same conversation I keep having about defence and government deployments, where "what does this thing do with our data" was never hypothetical. When I've worked on systems that need to run in those environments, the design questions come first: does this model need a live connection to five other services to do its job, or does it need read access to what's actually in front of it, for this one task, and nothing else. Broad, standing, cross-service access plus a memory that writes silently is a feature set that looks great in a demo and terrible in a threat model.
The fix Microsoft shipped closes this specific hole. It doesn't change the shape of the next one, because the shape is structural. Any assistant that combines always-on memory, multiple connected accounts, and a tool that can fetch external content is going to keep producing variants of CoSnitch, in different products, under different CVE numbers. The content an agent summarizes is untrusted input the same way a form field is untrusted input, and it needs to be treated with the same suspicion, not folded into the same context where authenticated queries run.
If you're building or buying an AI assistant that touches real accounts, ask what happens the day a webpage it reads is hostile, not if. Scope its memory writes so they're diffable and auditable. Scope its tool access so a summarization request can't also become a query against your calendar. And if you can't answer those questions about a product you already rely on, that's the finding, whether or not there's a patch note attached to it yet.
Assistants with memory and broad account access aren't a convenience feature bolted onto a chatbot. They're a new part of your attack surface, and most teams are still treating them like the former.