Copilot Reveals Its Own Vulnerability to Researchers
Researchers discovered a Microsoft 365 Copilot Enterprise vulnerability by asking the AI itself, which disclosed an undocumented parameter that bypasses user consent and enables data theft via a single link click.
The researchers initially wanted to create an exploit that would exfiltrate user data when a user merely clicked a link. Like most AI assistants, Copilot refused the request and said such sensitive actions require explicit user consent, such as pressing a return key or another key. In response, the researchers questioned Copilot about the guardrails that require user confirmation before the assistant can execute powerful commands. They asked why auto-execution was impossible, what URL structures and deep links were involved, and what happens when a page is loaded with input already in the prompt field. Each answer provided a further look into the safety mechanism and its limits. Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypasses the requirement for user consent. Ars Technica published the details of the research.