# Microsoft patches reported Copilot Personal data-exfiltration flaws

_Tuesday, August 18, 2026 at 1:47 PM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft patches reported Copilot Personal data-exfiltration flaws — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAc2Z6RvtNlJnjkfp-kCEhx8x8Q9XPLHY-oQb8NXu6cb-C5BTfa9HnmWq3G1GT3mPsHLV6Xf6tyBui-ljplsYEo9Qt8kBiNKXOwvTzACMisyS0NQ5U3bGg8O6yVEPStEPbYw4W-4ZasDNssDr2JTJD7GTo6QEpER1L-9Xci-mNSk3A5t_aLXGIHwo04FI/s1700-e365/copilot.jpg)

Varonis Threat Labs disclosed three flaws in consumer Copilot Personal that it said enabled a crafted link to auto-run an attacker prompt in an authenticated session, query already authorized connected services and send retrieved data to an attacker-controlled webhook. Varonis reported the issue to Microsoft in December 2025; the article says patches shipped August 18. The disclosure is tracked as CVE-2026-24301.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html)

---
Canonical: https://techandbusiness.org/newswire/6_7yLmW3-SR2EpoQ-x77kn
Retrieved: 2026-08-18T21:12:56.560Z
Publisher: Tech & Business (techandbusiness.org)
