Microsoft Copilot reveals secret input that allowed it to be hacked
Microsoft disclosed a hidden input in Copilot that let attackers steal passwords from users who clicked a crafted link.
Microsoft revealed that Copilot contained a secret, undocumented input parameter that allowed the assistant to be compromised. Attackers could abuse the hidden input to steal passwords when a target clicked a malicious link. The disclosure highlights hidden-parameter risks in widely deployed AI assistants.
58