• Sources: Varonis Threat Labs, Ars Technica, HN discussion, second HN thread
  • Summary: Varonis Threat Labs reports CVE-2026-24301, rated critical, disclosed to Microsoft in December 2025 with patches shipped 2026-08-18, and reports no evidence of exploitation in the wild. Three flaws chain: an undocumented URL parameter, autorun=1, that fires an attacker prompt supplied in ?q= on page load with no user gesture, exfiltration of connected Gmail, Drive, Calendar, chat history, and memory contents through Copilot's own URL fetch capability with the payload base64 encoded into the path, and indirect prompt injection via web summarization that writes attacker instructions into the persistent memory store. Varonis states the memory writes survive password changes, session revocation, and device re-enrollment, and that the researchers found the parameter by repeatedly asking Copilot why auto-execution was impossible until it named the parameter and its disabled protections, a technique they call meta-hacking. Copilot is a hosted service, so no client version scope applies and no affected version range is published: the fix is server side and shipped 2026-08-18. The two sources disagree on the affected product. Varonis, the primary source, describes Microsoft Copilot Personal at copilot.microsoft.com and dates disclosure to December 2025, while the Ars account describes Microsoft 365 Copilot for enterprise and states Microsoft silently mitigated the ?q= injection in February before shipping fuller fixes. This block follows Varonis, and the enterprise framing is not asserted here.
  • Why it matters: The exfiltration traffic is an ordinary outbound HTTPS GET from Copilot, so network-layer tooling sees nothing anomalous, and injected instructions held in memory persist through the account recovery steps a defender would normally take.
  • Follow-up: Track whether Microsoft publishes an advisory for CVE-2026-24301 naming the affected product, which would settle whether the enterprise framing holds.

send feedback on this story