Key facts
- Microsoft Copilot could be exploited via specially crafted URLs containing an undocumented parameter.
- The vulnerability allowed the AI assistant to execute prompts without user approval, accessing sensitive data.
- Researchers demonstrated the ability to extract email sender addresses and search for passwords within a user's inbox.
- Exfiltrated data was sent to attacker-controlled websites, encoded in base64 to conceal the theft.
- A separate attack vector involved poisoning Copilot's permanent memory to manipulate future interactions.
Researchers have identified a significant security flaw in Microsoft Copilot that could allow attackers to steal sensitive user data. The vulnerability involves the use of specially crafted URLs that embed prompts directly into the AI assistant's processing pipeline. By leveraging an undocumented parameter, attackers could circumvent security measures designed to prevent unauthorized actions, such as accessing user inboxes or searching for credentials.
