Copilot's own error messages leaked a hack
Archive item — written before sources were shown.
Varonis got Microsoft Copilot to reveal an undocumented URL parameter by interrogating its refusals, turning it into a one-click data-exfiltration exploit.
Security firm Varonis found it could extract an undocumented URL parameter from Microsoft Copilot simply by repeatedly asking it why certain requests were refused. Varonis senior researcher Lior Adar told Ars Technica:
“At the beginning, Copilot kept refusing, but every refusal revealed technical details about its internal architecture. Copilot eventually disclosed undocumented parameters. I took those parameters and used them for prompts for running automatically.”
The parameter, autorun=1, combined with Copilot’s existing q= parameter, let a crafted link fire a prompt automatically the moment a victim clicked it, no further interaction required. Researchers demonstrated using this to instruct Copilot to search a victim’s inbox, extract a sender’s email address or other sensitive data, base64-encode it, and silently send it to an attacker-controlled webhook. Microsoft mitigated the flaw in February, three months after Varonis reported it, by no longer honoring the parameter combination in that way.
What it means for you
The interesting failure here isn’t the exploit itself, it’s how it was found: an AI assistant’s refusal text acted as an oracle, incrementally confirming or denying guesses about its own internals until the researchers had a working attack. If you’re building or deploying an LLM-based agent that can take actions from URL parameters or embedded links, audit what your refusal and error messages actually reveal under repeated, adversarial questioning, not just whether the assistant blocks the bad request the first time. This is the same class of prompt-injection-via-links risk documented in a self-spreading prompt injection found in Copilot and an earlier Copilot data-theft flaw, worth reviewing alongside your own agent’s link-handling logic.
- 01Microsoft Copilot reveals secret input that allowed it to be hackedarstechnica.com · reporting, primary quotes
