Copilot told the researchers which parameter to abuse — then one link was enough to read the victim's mail
2026-08-19AI
Varonis found three linked flaws in consumer Copilot, tracked as CVE-2026-24301. An undocumented autorun parameter made a crafted link execute an attacker's prompt inside the victim's session with no further clicks, and a separate path wrote attacker instructions into Copilot's memory — where they survive a password change.