Microsoft Copilot reveals secret input that allowed it to be hacked

https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/

108 points · 4 comments · view on lemmy.world

4 Comments

ZebraGoose@sh.itjust.works · 68 pts · 6d (2 replies)

Tldr:

Security researchers tricked Microsoft Copilot into revealing a secret URL parameter (?autorun=1) that let malicious links make it run commands with zero user confirmation — just one click. Using this, they got Copilot to search victims' inboxes for passwords and send them to an attacker-controlled server, and also planted false "memories" in Copilot via hidden text on webpages. Microsoft has patched the issue, but the case shows how fragile AI assistants' safety guardrails can be.

Damarus@feddit.org · 49 pts · 6d (1 reply)

Autorun is back lmao

rockerface@lemmy.cafe · 17 pts · 6d

Now this is what we call backwards compatibility!

goatinspace@feddit.org · 3 pts · 6d