industry

Microsoft Copilot flaw exposed secret input that let hackers steal passwords

Summarized by AI from reporting by Ars Technica AI, published under our editorial policy.

Microsoft disclosed a secret parameter in Copilot that allowed hackers to steal passwords when a target clicked a malicious link. The flaw has been fixed, but the incident underscores how hidden vulnerabilities in AI systems can be exploited.

A close-up of a computer screen showing a warning message about a security flaw.

Key takeaways

  • Microsoft Copilot had a secret input parameter that allowed hackers to steal passwords when a target clicked a malicious link.
  • Microsoft has fixed the flaw, but the incident highlights the risks of hidden vulnerabilities in AI systems.
  • Users should enable two-factor authentication and be cautious about clicking on links from unknown sources.

Microsoft disclosed that Copilot, its AI assistant integrated into Microsoft 365, contained a secret input parameter that allowed hackers to steal passwords when a target clicked on a malicious link. The flaw has been fixed, but the incident underscores how hidden vulnerabilities in AI systems can be exploited.

## Secret parameter in Copilot allowed credential theft via malicious links Microsoft Copilot, an AI assistant integrated into Microsoft 365, had a hidden input parameter that was not meant to be accessible to users. Hackers discovered a way to exploit this parameter by crafting malicious links. When a user clicked on such a link, the hackers could intercept the user's credentials and gain access to their accounts. Microsoft has since fixed the flaw.

## Why this matters for everyday users This incident is a reminder that even trusted AI systems can have hidden vulnerabilities. For everyday users, this means being cautious about clicking on links, even if they seem to come from a trusted source. It also highlights the need for companies to be transparent about security flaws and to take steps to protect user data.

## Steps you can take to protect yourself To protect yourself, be cautious about clicking on links from unknown sources. If you use Microsoft Copilot, make sure you have the latest updates installed. You can also enable two-factor authentication on your accounts to add an extra layer of security.

Frequently asked

Is Microsoft Copilot safe to use now?
Microsoft has fixed the flaw, but users should still be cautious and keep their software updated.
How can I protect myself from similar attacks?
Enable two-factor authentication on your accounts and be cautious about clicking on links from unknown sources.