Microsoft Copilot reveals secret input that allowed it to be hacked
Summary
Ars Technica reports that researchers leveraged an undocumented Copilot prompt parameter to exfiltrate data when a user clicked a malicious URL. The exploit bypassed user consent via auto-execution and prompted memory manipulation, illustrating weaknesses in LLM guardrails. Microsoft patched the vulnerability by disabling the ?q= prompt injection into the chatbot input and requiring manual user input. The piece emphasizes the ongoing risk of prompt injections in enterprise AI copilots and reminds readers to remain vigilant with links and to monitor AI outputs.