原文开头
A chatbot is meant to answer questions, not explain how to break into itself. Yet while Varonis Threat Labs examined Copilot Personal, the assistant disclosed an undocumented web address parameter that transformed a prepared link into an automatic command. Researchers then used that detail to build a one-click attack capable of pulling information from connected accounts. The vulnerability chain, named CoSnitch, combined three weaknesses: automatic prompt execution, data extraction through connected services, and the ability to place lasting instructions inside Copilot’s memory. Microsoft classified the issue as critical under CVE-2026-24301. It was reported in December 2025 and patched on August 18, 2026. The researchers said they found no evidence that it had been exploited beyond their tests. …
摘自《科技生活新闻》(Techlife News)2026年8月22日。仅引用开头一小段供了解文章,版权归原刊所有,全文请阅读原刊。