Microsoft Copilot revealed an undocumented parameter to security researchers who were questioning its safeguards, giving them the missing piece needed to build an attack that could extract passwords and other sensitive information with a single click.
- Microsoft Copilot revealed an undocumented parameter to security researchers who were questioning its safeguards, giving them the missing piece needed to build an attack that could extract passwords and other sensitive information with a single click.
- Microsoft assigned the issue CVE-2026-42824 and remediated it.
- That could cause false information or attacker-selected instructions to remain in the assistant's stored memory.
The discovery was made by researchers at cybersecurity firm Varonis Threat Labs, who were investigating whether Copilot could be forced to execute a prompt without the user’s approval. Rather than reverse-engineering the system, they repeatedly asked Copilot why automatic execution was blocked.
The chatbot eventually disclosed technical details about its own security controls, including a hidden URL parameter called autorun=1. Researchers then used that information to construct a malicious link that could trigger a prompt automatically when opened by a user.
Varonis reported the vulnerability to Microsoft in December 2025. Microsoft subsequently changed how Copilot handled URL-based prompts and introduced further fixes this week.
Copilot Revealed the Missing Parameter
The researchers initially approached Copilot with what appeared to be a technical question about its safeguards.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseCopilot repeatedly explained that a user action was required before a prompt could execute. Researchers continued asking why automatic execution was not possible and what mechanisms prevented it.
Those answers gradually exposed details about the system’s URL handling and security controls.
Eventually, Copilot disclosed the undocumented autorun=1 parameter. According to Varonis, the parameter could cause a prompt supplied through another URL parameter to execute automatically under certain session conditions, without another visible confirmation from the user.
The researchers tested the information Copilot provided and found that the parameter worked despite the assistant’s own explanation that the mechanism had been disabled.
That allowed them to combine the hidden parameter with a previously known Copilot URL function and create a link capable of triggering an attacker-controlled prompt when clicked.
One Click Could Expose Sensitive Data
The attack depended on the victim already being authenticated to Copilot.
After the victim clicked the crafted link, Copilot could process the injected instructions using information and applications available within the user’s session. Researchers demonstrated techniques that could cause the assistant to retrieve information from connected services and send selected data to an external server controlled by an attacker.
Potentially exposed information included email addresses, inbox contents and credentials stored in emails or connected services, according to the research.
The attack did not require the victim to type a prompt into Copilot or approve the instruction after clicking the link.
Varonis called the attack chain CoSnitch.
The researchers also demonstrated a separate technique that could manipulate Copilot’s persistent memory through instructions hidden in webpage content. That could cause false information or attacker-selected instructions to remain in the assistant’s stored memory.
Microsoft Had Already Faced One-Click Copilot Attacks
CoSnitch is not the first one-click Copilot attack disclosed by Varonis this year.
In January, the company detailed Reprompt, an attack against Copilot Personal that could allow a single click on a legitimate Microsoft link to initiate a data-exfiltration chain. Varonis said the attack could continue operating against the user’s Copilot session even after the chat window was closed.
In June, Varonis disclosed SearchLeak, a separate attack against Microsoft 365 Copilot Enterprise. That vulnerability chain combined prompt injection with other web vulnerabilities to extract emails, calendar information and files available to the user’s account. Microsoft assigned the issue CVE-2026-42824 and remediated it.
The latest research adds a different element: the researchers obtained a key part of the attack by questioning the AI assistant about its own defenses.
Microsoft Changed Copilot’s URL Handling
Microsoft had already disabled the use of the q parameter to inject text directly into Copilot’s input field before the latest disclosure, according to Varonis. The company then introduced broader fixes after the researchers reported CoSnitch.
The research highlights a particular problem for AI assistants that can access email, files, calendars and other connected services. A malicious instruction does not necessarily need to break into those systems directly if the assistant already has permission to access them.
Varonis said the research showed how attackers could use Copilot’s own authorized access to retrieve information on behalf of a victim.
Microsoft had not provided a detailed public response to The Register by the time of its report.
The immediate risk from the disclosed CoSnitch technique has been addressed through Microsoft’s changes. But the sequence of Reprompt, SearchLeak and CoSnitch shows how researchers continue to find ways to turn ordinary AI features, URL handling and connected data access into new attack paths.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





