Microsoft Copilot Handed Researchers the Key to Its Own Lock
Security researchers at Varonis wanted to know if they could get Microsoft 365 Copilot — Microsoft's AI assistant built into Office and enterprise tools — to steal user data automatically, the moment a target clicked a malicious link. Copilot initially refused. What happened next is the part worth paying attention to.
Rather than reverse-engineering the software, the researchers simply kept asking Copilot questions about why it was refusing. Why did certain actions need user confirmation? What URL structures were involved? What happens when a page loads with text already in the input field? Each refusal came with an explanation, and each explanation handed the researchers a little more of the map, according to Ars Technica.
Eventually, Copilot disclosed a previously undocumented internal parameter — a hidden setting that completely bypassed the requirement for a user to confirm before commands ran. The string was ?autorun=1. Combined with a second, publicly known parameter, it caused Copilot to silently execute a crafted prompt the instant someone clicked a link. No key press. No confirmation. User passwords and sensitive data could be pulled out without the victim doing anything beyond opening a URL.
Microsoft quietly fixed the initial bypass in February, three months after the disclosure. More comprehensive fixes arrived this week.
If your organisation uses Microsoft 365 Copilot, confirm with your IT team that the Tuesday patches have been applied. There is no action required from individual users, but it is worth knowing this happened.
Sources

