Back to News
Technology
Aug 20, 202614 views2 min read

Microsoft Patches CoSnitch Vulnerability in Copilot After Eight-Month Delay

Microsoft released a security patch for a vulnerability called CoSnitch in its Copilot AI assistant, eight months after the flaw was first identified. The bug could have allowed attackers to extract sensitive information from Copilot interactions. The delayed fix drew criticism from cybersecurity researchers who say AI systems require faster response times given how quickly vulnerabilities can be exploited.

Microsoft Patches CoSnitch Vulnerability in Copilot After Eight-Month Delay

Microsoft released a patch for a security vulnerability in its Copilot AI assistant called CoSnitch, eight months after the flaw was first identified by researchers.

The vulnerability could have allowed attackers to extract sensitive information from Copilot interactions, potentially exposing data from business users who rely on the tool for tasks involving confidential documents and communications.

Cybersecurity researchers criticized the eight-month delay, arguing that AI systems require faster patch cycles than traditional software because the attack surface is broader and the potential for exploitation grows as more users adopt the tools.

Microsoft did not publicly disclose the details of how the vulnerability worked or how many users may have been affected during the period it remained unpatched. The company said it found no evidence of active exploitation before the fix was released.

The CoSnitch patch was part of a broader set of security updates released by Microsoft in August 2026. Apple also patched a critical image-processing vulnerability around the same time, and OpenAI tightened safety controls on its Astra model due to potential cybersecurity risks.

The incidents highlight growing concerns about security in AI products as they become more deeply integrated into business workflows. Researchers say the combination of AI's access to sensitive data and its complexity makes it a high-value target for attackers, and that companies need to treat AI security with the same urgency as traditional software vulnerabilities.