THE VERDICT
● CoSnitch hit Personal only. Microsoft states enterprise customers were unaffected and no customer action is required.
● But do not read that as enterprise being safe. SearchLeak, an earlier Varonis finding this year, turned Microsoft 365 Copilot Enterprise into a silent exfiltration channel.
● The real difference: who controls the connectors. On Personal, the user does. On Enterprise, an admin does — and that is the whole security argument.
Head to head
|
Copilot Personal |
Microsoft 365 Copilot |
| Affected by CoSnitch |
Yes, patched 18 Aug 2026 |
No, per Microsoft |
| Affected by SearchLeak |
Not the reported target |
Yes |
| Who approves connectors |
The individual user |
Tenant administrator |
| Typical reach |
Personal Gmail, Drive, Calendar |
Corporate mail, SharePoint, Teams |
| Blast radius if breached |
One person |
Whatever that account can reach |
| Central audit trail |
None |
Tenant logging available |
The distinction that actually matters
Reading "enterprise was unaffected" as "enterprise is safer" gets the causation backwards. Both products expose the same architectural pattern: an assistant with broad connector access, a persistent memory store, and a model that will explain its own behaviour to anyone who asks patiently.
What Enterprise adds is not a different architecture. It is governance over that architecture — an admin decides which connectors exist, tenant logging captures access, and there is somebody whose job it is to review it. On Personal, the person approving Gmail access is the person who wanted the feature five seconds earlier.
THE GAP NEITHER PRODUCT CLOSES
The CoSnitch memory poisoning wrote no process, no file, no network connection and no log entry. It was visible only inside Copilot's memory interface. Tenant logging does not help if the artefact never touches a logged surface. Enterprise governance narrows who can connect what. It does not yet see inside assistant memory.
What to do on each
| If you are on... |
Do this |
| Copilot Personal |
Read your memory entries, then remove every connector you are not using |
| Microsoft 365 Copilot |
Audit tenant-approved third-party apps and confirm your tooling can see assistant-originated access |
| Both, personally and at work |
Keep personal mail off the work assistant and vice versa. Mixed reach is the real risk |
| Deciding between them |
Enterprise, for anything touching company data. The governance layer is the product |
FAQ
Was Microsoft 365 Copilot affected by CoSnitch?
Microsoft says no, and that no customer action is required. CoSnitch was scoped to Copilot Personal.
So is the enterprise version secure?
It has better governance, not different architecture. SearchLeak, disclosed earlier this year by the same researchers, did affect Microsoft 365 Copilot Enterprise.
Does tenant logging catch memory poisoning?
Not on the evidence from CoSnitch. The memory write produced no logged artefact at all — it appeared only in the assistant's own memory interface.
What is the single highest-value control?
Reducing connectors. Every integration you remove shrinks the blast radius of every future flaw in this class, on either product.