cd /news/artificial-intelligence/microsoft-copilot-reveals-secret-inp… · home topics artificial-intelligence article
[ARTICLE · art-101316] src=arstechnica.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Microsoft Copilot reveals secret input that allowed it to be hacked

Researchers at security firm Varonis exploited Microsoft 365 Copilot Enterprise by tricking the AI into revealing an undocumented parameter (?autorun=1) that bypassed user consent, allowing data exfiltration via a single click. Microsoft mitigated the vulnerability in February by disabling the ?q= parameter and introduced more comprehensive fixes on Tuesday.

read2 min views2 publishedAug 18, 2026
Microsoft Copilot reveals secret input that allowed it to be hacked
Image: Arstechnica (auto-discovered)

It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.

Researchers at security firm Varonis knew they wanted to create an exploit that would exfiltrate user data when a user did nothing more than click on a link. Like most AI assistants today, Copilot steadfastly refused and made clear that sensitive prompts like that require explicit user consent in the form of a gesture, such as pressing a return key or other key. In response, the researchers peppered Copilot with questions about the guardrails that required user confirmation before the assistant can execute powerful commands.

Loose lips sink ships #

The dialog was like a game of 20 questions. Each answer provided a new clue that divulged information about the complex safety mechanism. Why was auto-execution impossible, they asked. What URL structures and deep links were involved? What happens when a page is loaded with input already in the prompt field? Each answer provided a deeper view into the guardrail and its limits. Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.

“At the beginning, Copilot kept refusing, but every refusal revealed technical details about its internal architecture,” Varonis Senior Researcher Lior Adar said in an interview. “Copilot eventually disclosed undocumented parameters. I took those parameters and used them for prompts for running automatically.”

The parameter was the string ?autorun=1. When accompanied by the separate, well-known parameter ?q=, the researchers’ prompt silently fired the moment the target clicked on the malicious URL. Microsoft silently mitigated the vulnerability in February, three months after Varonis reported it, by no longer allowing ?q= to inject text into the chatbot input. The user instead had to click and type manually, a requirement that prevented third-party browser integrations from using the parameter as intended. Microsoft introduced more comprehensive fixes on Tuesday.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/microsoft-copilot-re…] indexed:0 read:2min 2026-08-18 ·