Security
Microsoft patches reported Copilot Personal data-exfiltration flaws
Image: Primary Varonis Threat Labs disclosed three flaws in consumer Copilot Personal that it said enabled a crafted link to auto-run an attacker prompt in an authenticated session, query already authorized connected services and send retrieved data to an attacker-controlled webhook. Varonis reported the issue to Microsoft in December 2025; the article says patches shipped August 18. The disclosure is tracked as CVE-2026-24301.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
