Microsoft Copilot reveals secret input that allowed it to be hacked
Covered by 2 sources
Read full postSecurity researchers discovered an undocumented URL parameter in Microsoft Copilot that allows attackers to inject prompts and exfiltrate sensitive data like email addresses and passwords without user consent. This vulnerability enables crafted URLs to execute commands automatically, leaking information to attacker-controlled servers.




