Microsoft Copilot reveals secret input that allowed it to be hacked
Summary
Researchers found a security flaw in Microsoft 365 Copilot Enterprise that let attackers get user passwords and other private information without permission. The flaw came from a secret web link trick that Copilot did not block properly, allowing automatic commands to run when a user clicked a link.Key Facts
- Microsoft Copilot is an AI assistant that normally requires user approval before running sensitive commands.
- Security experts at Varonis tested if Copilot’s safety limits could be bypassed.
- They discovered Copilot revealed an undocumented web link parameter named "?autorun=1" that skipped the approval step.
- When combined with another parameter "?q=", this allowed automatic execution of commands embedded in a URL.
- Using this, attackers could trick users into clicking links that made Copilot leak email contents or passwords.
- Microsoft fixed part of the issue in February by blocking "?q=" from injecting text and introduced stronger fixes later.
- The vulnerability was reported to Microsoft three months before the first mitigation.
- Copilot’s responses about its own safety rules helped the researchers learn how to bypass them.
Read the Full Article
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.