Security researchers at Varonis discovered a critical vulnerability in Microsoft 365 Copilot Enterprise that let attackers steal user passwords without explicit consent. The exploit relied on an undocumented prompt parameter, which Copilot revealed during a probing question-and-answer session about its safety mechanisms.
The researchers tested Copilot’s guardrails by asking why auto-execution required user confirmation. Through iterative questions, they uncovered details about URL structures, deep links, and input handling. Copilot ultimately disclosed a Microsoft trade secret: a hidden parameter that bypassed the consent requirement entirely.
Microsoft has not yet commented on the disclosure. The exploit highlights risks in AI assistants that rely on undocumented parameters for security controls.


