Microsoft Copilot was found to be vulnerable to hacking due to a secret input parameter, allowing attackers to steal passwords. The vulnerability was discovered and publicly revealed by researchers.
According to a report from Ars Technica, a secret parameter within Microsoft Copilot allowed hackers to compromise user accounts when a target clicked on a specially crafted link. The vulnerability centered around how Copilot processed certain inputs, creating an opening for malicious actors.
The report details that the flaw enabled attackers to steal passwords. The method involved exploiting a hidden input that bypassed security measures, allowing the extraction of credentials when a user interacted with a malicious link. Researchers have since revealed the specific input that enabled the hack.
Microsoft has not yet issued a public statement regarding the vulnerability, but the revelation highlights the ongoing security challenges associated with large language models and AI-powered tools. The discovery underscores the importance of rigorous security testing and the need to address potential weaknesses in these increasingly prevalent technologies.
We don't rate truth. We strip the spin and show you which perspectives covered the story. You decide.
Read the original coverage
💬 Comments
📜 Comment Policy