You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 24307
About this tag
CVE-2026-24307, also known as the Reprompt vulnerability, is a high-impact information-disclosure flaw in Microsoft's Copilot Personal assistant. Discovered by Varonis Threat Labs, it exploits a design weakness in how Copilot handles prompt content embedded in links. A single-click chain could trick Copilot into leaking small pieces of user context and session data to an attacker-controlled endpoint. Microsoft addressed the issue during the January 2026 update cycle. The incident highlights ongoing engineering and operational challenges with general-purpose LLM assistants, particularly around prompt injection and data security. This tag covers discussions, disclosures, and mitigations related to CVE-2026-24307 on WindowsForum.
A high‑impact information‑disclosure flaw in Microsoft’s Copilot family of assistants — widely discussed under the researcher name “Reprompt” and tracked by some vendors as CVE‑2026‑24307 — exposed a design weak‑spot in how Copilot handled prompt content embedded in links, enabling a...