Microsoft Copilot Exposed the Secret Input That Led to Its Own Compromise

Security researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot by simply asking the AI to explain its own guardrails. Through a series of targeted questions, Copilot revealed an undocumented prompt parameter that completely bypassed the requirement for explicit user consent.

The exploit allowed attackers to exfiltrate sensitive user data when a victim merely clicked a link. This unusual method of vulnerability discovery highlights how AI assistants can inadvertently disclose their own security weaknesses.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleOpenAI’s Expensive Smart Speaker Will Use Moving Parts to Feel “More Alive”
Start typing to search