Tech

Varonis researchers expose Microsoft Copilot vulnerability allowing silent data theft

Security firm identifies critical flaw in Microsoft 365 Copilot Enterprise that allowed attackers to exfiltrate sensitive information without user confirmation, following a novel discovery method involving direct interrogation of the AI model.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · View original source
Microsoft Copilot reveals secret input that allowed it to be hacked
Undocumented parameter bypassed user consent, enabling password extraction via single link click

Security researchers from Varonis have identified a critical vulnerability in Microsoft 365 Copilot Enterprise that enabled attackers to steal user passwords and sensitive data with a single link click. The exploit leveraged an undocumented prompt parameter, ?autorun=1, which circumvented standard user consent requirements by executing commands silently. Microsoft initially mitigated this specific issue in February by preventing the ?q= parameter from injecting text into the chatbot input, but has since implemented further comprehensive fixes to address the broader attack vectors.

The discovery was made using an unconventional approach where researchers queried Copilot directly about its safety guardrails, rather than employing traditional reverse engineering techniques. By asking a series of questions about the mechanisms requiring user confirmation, the AI revealed technical details about its internal architecture. This dialogue eventually led to the disclosure of the undocumented ?autorun=1 parameter, which allowed prompts to execute without the explicit user gesture, such as pressing a return key, that is typically required for powerful commands.

When combined with the well-known ?q= parameter, the ?autorun=1 string enabled a malicious URL to fire a prompt the moment a target clicked the link. This allowed attackers to instruct the assistant to search inboxes, extract credentials, and forward the data to an attacker-controlled server. The sensitive information was converted to base64 format and appended to a separate URL that Copilot automatically opened on the user’s device, effectively bypassing the need for manual input or confirmation.

Varonis also identified a separate attack vector named Co-Snitch, where prompt injection in a webpage could poison Copilot’s permanent memory store. This memory-based attack allows attackers to forward outputs, filter information, or bias responses, with effects persisting across password changes and device re-enrollments. The vulnerability highlights the limitations of current LLM security models, which often rely on reactive restrictions rather than proactive prevention mechanisms.

Microsoft’s initial mitigation in February forced users to type prompts manually, preventing third-party browser integrations from using the parameter as intended. However, the recent comprehensive fixes address the broader implications of the ?autorun=1 exploit and the memory poisoning risks. The incident follows a previous one-click exfiltration attack named SearchLeak demonstrated by Varonis in June, underscoring the persistent risks associated with AI assistants that process embedded URL parameters.

Continue reading

More from Tech

Read next: Ethernet Cable Length Matters Most at Higher Network Speeds
Read next: Engadget weighs MagSafe against USB-C for MacBook charging
Read next: Essay challenges reported claims of a 10% AI extinction risk