Microsoft Copilot Vulnerability Allowed Hackers to Steal Passwords

Photo: Ars Technica
Quick answer
A vulnerability in Microsoft Copilot enabled hackers to steal passwords through specially crafted links containing a secret input parameter.
Cybersecurity researchers uncovered a serious vulnerability in Microsoft Copilot’s AI assistant that could lead to password theft and other data breaches. The issue stemmed from an undocumented parameter enabling hackers to craft malicious links.
Clicking such a link inadvertently executed hidden code, transmitting data to attackers. The flaw affected Copilot’s enterprise versions, posing significant risks for businesses relying on the tool for workflow automation.
Microsoft confirmed the breach and stated it had been resolved. The company emphasized that the incident did not result in widespread leaks but urged users to update their software to prevent future threats.
Experts note that the Copilot incident is not the first case of AI systems becoming attack targets. Developers are advised to strengthen security controls for such solutions, especially in corporate environments.
Common questions
- How did hackers exploit the Copilot vulnerability?
- Attackers identified an undocumented input parameter that allowed malicious code injection into Copilot’s responses. Clicking a prepared link triggered data exfiltration.
- What data could be compromised?
- Primarily, the flaw threatened passwords and other sensitive information processed by Copilot. The exact scope of leaks depends on the attack scenario.
- Has the vulnerability been fixed?
- Yes, Microsoft patched the issue after researchers reported it. Users are advised to update their systems to mitigate future risks.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml