Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Microsoft issued a patch for a critical Copilot vulnerability in the personal version, nearly eight months after confirmation, according to Microsoft and Varonis. Varonis reported the CoSnitch flaw, involving auto-execution, data exfiltration, and persistent memory poisoning. Microsoft said customers are protected and no action is needed.
How this was made

The 30-second read
Why it matters
The patch reduces the immediate exploitability of the CoSnitch chain, but the narrative emphasizes architectural limitations of LLMs separating data from instructions, suggesting longer-term mitigation rather than a clean fix.
Market read
Traders may monitor AI security remediation headlines for Microsoft and peers, but this is not accompanied by financial metrics or a confirmed active breach in the article.
What to watch
The article notes a potentially inaccurate statement about enterprise Copilot not being affected and highlights Copilot Fusion unification risk, which could extend exposure beyond the personal Copilot scope.
Background
Varonis reported multiple Copilot vulnerabilities in 2026 (Reprompt, SearchLeak, and CoSnitch), with CoSnitch relying on prompt execution, data exfiltration, and persistent memory poisoning.
Ticker impact
Microsoft issued a critical patch for the CoSnitch one-click Copilot vulnerability after confirming the flaw and labeling it critical via MSRC.
Limited direct price impact expected, but cybersecurity and AI governance headlines can drive short-lived sentiment swings.
The article is primarily a security disclosure and fix timeline, not a financial guidance change. However, it highlights potential broader Copilot surface area and a multi-flaw exploit chain, which can affect perceived operational risk and enterprise adoption sentiment.
Market effects
Reinforces that LLM agent systems face prompt-injection and memory-poisoning risks, likely increasing scrutiny of AI guardrails across the software sector.
Primarily US-listed software sentiment, with spillover to global enterprise security budgets and vendor risk assessments.
Security disclosures like this can accelerate global compliance and procurement requirements for AI assistants.
Counterpoint
Microsoft says customers are already protected and no action is needed, so the market may treat this as routine remediation rather than a new breach or earnings-relevant event.
Key entities
- companyMicrosoft
Issued a critical MSRC-labeled patch for the CoSnitch one-click Copilot vulnerability and stated customers are already protected.
- companyVaronis
Discovered and disclosed CoSnitch and previously reported other Copilot bugs (Reprompt, SearchLeak).
- research_firmInfo-Tech Research Group
Analyst commentary highlights the novelty of chaining multiple exploit vectors and recommends disabling Copilot as a mitigation.




