Microsoft Copilot Leaked Passwords Via Secret Parameter
Researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot by simply asking the AI to explain its own security guardrails. Through a series of probing questions, Copilot revealed an undocumented parameter, autorun=1, that bypassed user consent requirements entirely.
Combined with the known q= parameter, attackers could craft a malicious URL that silently executed prompts the moment a victim clicked it, stealing passwords and sensitive data from inboxes. Microsoft quietly applied a partial fix in February and released comprehensive patches Tuesday.
