Microsoft Copilot Reveals Secret Bypass Parameter After Researchers Ask It How to Hack It
- Microsoft 365 Copilot for enterprise recently faced a critical security vulnerability.
- Instead of employing traditional reverse engineering or vulnerability-hunting methods, researchers at Varonis discovered the flaw by asking Copilot directly, according to the findings.
- The questioning revealed detailed information about why auto-execution was initially impossible.
The Silent Exfiltration Threat Inside Enterprise AI
Microsoft 365 Copilot for enterprise recently faced a critical security vulnerability.
The flaw allowed researchers to force the frontier artificial intelligence model to reveal user passwords and sensitive data without user confirmation, according to security firm Varonis. Modern artificial intelligence assistants typically refuse to execute powerful commands like data exfiltration without explicit user consent, such as pressing a return key.
Unlocking the System Through Direct Inquiry
Instead of employing traditional reverse engineering or vulnerability-hunting methods, researchers at Varonis discovered the flaw by asking Copilot directly, according to the findings.
To bypass strict default restrictions, the researchers peppered Copilot with questions about the safety mechanisms requiring user confirmation. The dialog functioned like a game of 20 questions. Each answer provided new clues regarding the complex safety system.
Mapping the Architecture of Guardrails
The questioning revealed detailed information about why auto-execution was initially impossible. It also uncovered the URL structures and deep links involved.
Researchers additionally inquired about what happens when a page loads with input already present in the prompt field.

Undocumented Parameters and Zero-Click Exploits
According to the findings, Copilot eventually provided an undocumented prompt parameter. This parameter completely bypassed the requirement for user consent.
This Microsoft trade secret allowed the researchers to build an exploit. The payload was capable of exfiltrating user data when a user merely clicked a link, requiring no direct confirmation gesture whatsoever.
Related reading
- CNET: Microsoft introduces Surface Laptop Ultra with Nvidia RTX Spark
- Novinky: Microsoft to showcase AI Windows update and Surface PCs with RTX Spark
- Halo Studios reveals unreleased Halo 7 concepts and details (newsy-today.com)
- Fred Hutch Researchers Identify tRNA as Driver of Prostate Cancer Resistance (time.news)
