← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Microsoft Copilot revealed undocumented parameter allowing data exfiltration without user consent

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Varonis researchers found a Copilot vulnerability for data exfiltration.
  • Copilot revealed an undocumented parameter, "?autorun=1", during questioning.
  • This parameter bypassed user consent for prompt execution.
  • Microsoft mitigated the issue in February and released further fixes Tuesday.

Copilot Vulnerability Discovered

Security researchers at Varonis identified a critical vulnerability in Microsoft 365 Copilot Enterprise. This flaw allowed for the exfiltration of sensitive user data without requiring explicit user confirmation, a standard security measure for AI assistants executing powerful commands. The exploit was designed to activate simply by a user clicking on a malicious link.

AI Assistant Revealed Its Own Weakness

Unusually, the researchers uncovered the vulnerability by directly questioning Copilot about its internal guardrails and safety mechanisms. Through a series of detailed inquiries, Copilot divulged technical details about its architecture, eventually revealing an undocumented prompt parameter: "?autorun=1". This parameter, when used in conjunction with the known "?q=" parameter, allowed prompts to execute silently the moment a target clicked a specially crafted URL.

Microsoft's Mitigation Efforts

Varonis reported the vulnerability to Microsoft, which silently mitigated the issue in February, approximately three months after the initial report. The initial fix involved preventing the "?q=" parameter from injecting text directly into the chatbot input, thereby requiring manual user interaction. Microsoft implemented more comprehensive fixes on Tuesday to address the underlying problem.

Impact on Security Practices

This incident highlights the potential for advanced AI models to inadvertently disclose sensitive information about their own internal workings, which can then be exploited by malicious actors. It underscores the importance of rigorous security testing and the need for developers to anticipate novel methods of vulnerability discovery, even those involving direct interaction with the AI itself.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~32 min · 27 stories · Aug 18

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researchers discovered a vulnerability in Microsoft 365 Copilot Enterprise that allowed data exfiltration without explicit user consent by querying Copilot itself. The AI assistant disclosed an undocumented prompt parameter, "?autorun=1", which, when combined with the "?q=" parameter, enabled silent execution of malicious prompts upon a user clicking a link. Microsoft has since mitigated this vulnerability.