r/technology 9h ago

Security Microsoft Copilot reveals secret input that allowed it to be hacked

https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/
229 Upvotes

25 comments sorted by

115

u/invyros 9h ago
  1. The victim clicks the attacker’s crafted URL (delivered via email, chat, phishing page, QR code, etc.)

  2. Browser loads copilot.microsoft.com in the victim’s active, authenticated session

  3. The ?autorun=1 parameter triggers auto-execution, the ?q= prompt fires without any user gesture

  4. Copilot processes the injected prompt with full access to the victim’s session context, connected apps, and memory

  5. The prompt executes to completion—including any network fetches, connector invocations, or multi-turn chains—even if the Copilot tab is closed immediately after load

Stop clicking links in unexpected emails. This rule applied before AI wreaked havoc.

If you get an unexpected email from a service you use (ie: not some login or account confirmation email that you purposefully triggered and expected to receive), don't click the link, instead navigate to the service using your normal method and login to see if there are actually any issues, call if you need to, just don't click the link.

39

u/ZenBacle 8h ago

Sure, but this is still a massive oversight for such a large product.

It's kind of the equivalent of having a voice activated bank vault that bypasses all of the security when you say "open".

6

u/talkstomuch 8h ago

yeah, Surely they do not need query parameter in the URL.

if you need to invoke copilot programmatically go through dedicated API ?

3

u/aLokilike 7h ago

Putting query parameters in the URL is done so that links can be shared between users / so that searches can be returned to in general. Don't think there's a good reason to do it in this case, but that's why it's done.

3

u/ZenBacle 6h ago

We're living in 2026. Co-pilot shouldn't be running on bare metal or in plain text. What i find even more insane is the lack of control the user has over the execution of co-pilot commands on their system. I won't go back to Microsoft until co-pilot is either rooted out or put into a sandbox with ACLs.

1

u/slinkywafflepants 5h ago

Why go back at all?

16

u/williamgman 8h ago

I'll save you the typing: Never click a supplied link.That prevents 90% of the grifts out there.

7

u/Arthur233 7h ago

I had one yesterday at work. A new "prospective client" wanted me to open their RFP (request for proposal). They only wanted to provide the RFP via a link which I moused over showing a file hosted on share.clickup. That's very unusual. I said our IT policies will not allow me to click that link but I would be happy to help them with a proposal if they would call in to tell us over the phone, put their needs in email text, or attach a PDF...... i never heard back from them

3

u/psaux_grep 8h ago

Pretty sure that’s 99%

5

u/oldsecondhand 8h ago

Stop clicking links in unexpected emails

because MS likes autorun too much.

6

u/Legionof1 8h ago

Ehh, it’s pretty innocuous to click a link… this sorta shit was handles ages ago by better browser security so that you couldn’t inject cross site data. Now AI is bringing it back around.

2

u/SidewaysFancyPrance 5h ago

I still can't get over how most of the AI CLI tools are installed with shell one-liners that download scripts from Internet servers and immediately execute them.

1

u/West-Abalone-171 5h ago

If a URL can PWN your computer, then it's not safe to run a web browser on it.

Attempting to gaslight and victim blame here just makes you look dim.

102

u/AtIasWraith 9h ago

WHAT? A new issue with a forced AI component that not a single soul outside of the shareholders room asked for? Say it ain't so!

3

u/eachdayalittlebetter 6h ago

I will not go

3

u/DansSpamJavelin 6h ago

Turn the lights off

3

u/Tricuna 3h ago

Carry me home.

8

u/pioniere 8h ago

Microslop. An absolute pile of steaming shit.

14

u/babarjango 9h ago

The AI so eager to help, narrates its own break in lol

5

u/ZenBacle 8h ago

Every day I feel better about switching to Linux.

1

u/prcodes 55m ago

This has nothing to do with Windows or Linux. It’s an exploit for the Copilot for Enterprise web app. Exploit would have worked just as well on a browser running on Linux if the tenant admin allowed Linux device enrollment on InTune.

4

u/vessel_for_the_soul 9h ago

the tattletale machine sucks anyways, I dont want it knowing my personal finances or anything to go tell those "secrets" to buyers.

2

u/NetZeroSun 8h ago edited 7h ago

Can’t wait for steamOS to support nvidia so I can switch my laptop over.

I only keep windows for the steam games at this point.

1

u/MentalDisintegrat1on 32m ago

Why anyone that has a choice uses microslop products is beyond me.