ZeroHour
Ars Technica · Securitypublished ()ingested Dan Goodin 1

Microsoft Copilot reveals secret input that allowed it to be hacked

mediumAI safety & security exploited in the wildimportance 58
AI summary · glm-5.3-flash

Microsoft disclosed a hidden input in Copilot that let attackers steal passwords from users who clicked a crafted link.

Microsoft revealed that Copilot contained a secret, undocumented input parameter that allowed the assistant to be compromised. Attackers could abuse the hidden input to steal passwords when a target clicked a malicious link. The disclosure highlights hidden-parameter risks in widely deployed AI assistants.

  • Secret input parameter in Microsoft Copilot enabled attacks
  • Password theft required the victim to click an attacker link
  • Microsoft publicly disclosed the issue; technical details remain limited
VendorsMicrosoft
OrganizationsMicrosoft
Full article

Secret parameter allowed hackers to steal passwords when a target clicked on a link.

This source does not provide full text. Read it at arstechnica.com.