Security researchers at Varonis developed an exploit that could steal user data from Microsoft 365 Copilot when a victim merely clicked a link. Copilot initially refused to execute the attack, stating that sensitive operations require explicit user consent.
By asking Copilot a series of questions about its own guardrails, the researchers got it to disclose an undocumented prompt parameter that bypassed the consent requirement altogether. This allowed them to carry out the data exfiltration without any user confirmation.
Comments