Microsoft Copilot reveals secret input that allowed it to be hacked

Security researchers discovered a vulnerability in Microsoft 365 Copilot by using the AI assistant itself to reveal undocumented prompt parameters. This exploit allowed the researchers to bypass safety guardrails that normally require user confirmation for sensitive actions.
Why it matters
This highlights the risks of 'prompt injection' and the potential for AI models to inadvertently disclose their own security mechanisms when queried by sophisticated users.
COSNITCH Microsoft Copilot reveals secret input that allowed it to be hacked Secret parameter allowed hackers to steal passwords when a target clicked on a link.
16 Credit: Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images Credit: Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in