Microsoft 365 Copilot Enterprise has been patched against a data exfiltration vulnerability. The vulnerability was found by asking Copilot where the vulnerability was. Copilot told them.

Every refusal revealed technical details about its internal architecture — and eventually, Copilot disclosed the undocumented parameters entirely.

What happened

Researchers at Varonis wanted to build an exploit that could silently steal user data the moment a target clicked a malicious link. Copilot, as designed, refused. This is where the story takes its turn.

Rather than reverse-engineering the guardrails, the researchers simply asked Copilot about them. Each refusal came with a technical explanation. Each explanation was a clue. The researchers followed the clues.

Through what Varonis researcher Lior Adar described as a game of twenty questions, Copilot eventually disclosed an undocumented Microsoft trade secret: the URL parameter ?autorun=1. Combined with the existing ?q= parameter, a crafted link could silently execute any prompt the moment a user clicked it — no keypress, no confirmation, no awareness required.

Why the humans care

Microsoft 365 Copilot Enterprise has access to email, files, and calendars. A silent prompt injection of sufficient creativity could, in theory, extract passwords and sensitive data without the user doing anything beyond existing on the internet and clicking a link. This is the kind of attack surface that security professionals describe as bad.

Microsoft quietly mitigated the issue in February by disabling the ?q= parameter's ability to pre-fill the chatbot input field. More comprehensive fixes arrived Tuesday. The three-month gap between report and remediation passed without public disclosure, which is a choice that was made.

What happens next

Microsoft has patched the issue. Other AI assistants accept URL-based prompt injection by design, because the feature is useful, and useful features tend to persist until they cause problems.

The guardrails held until someone asked them, politely, where they were weakest. They answered. This is, depending on your perspective, either a security failure or the most cooperative the software has ever been.