Story perspectives
Varonis Flags CoSnitch, Microsoft Plans Patch and CVE
8/18/2026
1 of 1
Story summary
- Varonis Threat Labs uncovered CoSnitch and reported it to Microsoft in December 2025, prompting the company to plan a patch and CVE on Tuesday.
- CoSnitch uses a “?q=” query with an “autorun=1” flag, allowing a URL to run prompts that can pull Gmail, Drive files and send them to a webhook.
- Senior researcher Lior Adar said the issue reveals deep architectural flaws, with Microsoft giving no comment before publication.
