Microsoft Copilot reveals secret input that allowed it to be hacked
AI summary · glm-5.3-flash
Microsoft disclosed a hidden input in Copilot that let attackers steal passwords from users who clicked a crafted link.
Microsoft revealed that Copilot contained a secret, undocumented input parameter that allowed the assistant to be compromised. Attackers could abuse the hidden input to steal passwords when a target clicked a malicious link. The disclosure highlights hidden-parameter risks in widely deployed AI assistants.
- Secret input parameter in Microsoft Copilot enabled attacks
- Password theft required the victim to click an attacker link
- Microsoft publicly disclosed the issue; technical details remain limited
Full article
Secret parameter allowed hackers to steal passwords when a target clicked on a link.
This source does not provide full text. Read it at arstechnica.com.