The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
AI

Microsoft Copilot Spilled Its Own Secret About a Hidden Parameter Used to Steal Passwords With One Click

The discovery was made by researchers at cybersecurity firm Varonis Threat Labs, who were investigating whether Copilot could be forced to execute a prompt without the user's approval.

Microsoft Copilot Spilled Its Own Secret About a Hidden Parameter Used to Steal Passwords With One Click

Microsoft Copilot revealed an undocumented parameter to security researchers who were questioning its safeguards, giving them the missing piece needed to build an attack that could extract passwords and other sensitive information with a single click.

Key Takeaways
  • Microsoft Copilot revealed an undocumented parameter to security researchers who were questioning its safeguards, giving them the missing piece needed to build an attack that could extract passwords and other sensitive information with a single click.
  • Microsoft assigned the issue CVE-2026-42824 and remediated it.
  • That could cause false information or attacker-selected instructions to remain in the assistant's stored memory.
Listen to this article
READY

The discovery was made by researchers at cybersecurity firm Varonis Threat Labs, who were investigating whether Copilot could be forced to execute a prompt without the user’s approval. Rather than reverse-engineering the system, they repeatedly asked Copilot why automatic execution was blocked.

The chatbot eventually disclosed technical details about its own security controls, including a hidden URL parameter called autorun=1. Researchers then used that information to construct a malicious link that could trigger a prompt automatically when opened by a user.

Varonis reported the vulnerability to Microsoft in December 2025. Microsoft subsequently changed how Copilot handled URL-based prompts and introduced further fixes this week.

Copilot Revealed the Missing Parameter

The researchers initially approached Copilot with what appeared to be a technical question about its safeguards.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

Copilot repeatedly explained that a user action was required before a prompt could execute. Researchers continued asking why automatic execution was not possible and what mechanisms prevented it.

Those answers gradually exposed details about the system’s URL handling and security controls.

Eventually, Copilot disclosed the undocumented autorun=1 parameter. According to Varonis, the parameter could cause a prompt supplied through another URL parameter to execute automatically under certain session conditions, without another visible confirmation from the user.

The researchers tested the information Copilot provided and found that the parameter worked despite the assistant’s own explanation that the mechanism had been disabled.

That allowed them to combine the hidden parameter with a previously known Copilot URL function and create a link capable of triggering an attacker-controlled prompt when clicked.

One Click Could Expose Sensitive Data

The attack depended on the victim already being authenticated to Copilot.

After the victim clicked the crafted link, Copilot could process the injected instructions using information and applications available within the user’s session. Researchers demonstrated techniques that could cause the assistant to retrieve information from connected services and send selected data to an external server controlled by an attacker.

Potentially exposed information included email addresses, inbox contents and credentials stored in emails or connected services, according to the research.

The attack did not require the victim to type a prompt into Copilot or approve the instruction after clicking the link.

Varonis called the attack chain CoSnitch.

The researchers also demonstrated a separate technique that could manipulate Copilot’s persistent memory through instructions hidden in webpage content. That could cause false information or attacker-selected instructions to remain in the assistant’s stored memory.

Microsoft Had Already Faced One-Click Copilot Attacks

CoSnitch is not the first one-click Copilot attack disclosed by Varonis this year.

In January, the company detailed Reprompt, an attack against Copilot Personal that could allow a single click on a legitimate Microsoft link to initiate a data-exfiltration chain. Varonis said the attack could continue operating against the user’s Copilot session even after the chat window was closed.

In June, Varonis disclosed SearchLeak, a separate attack against Microsoft 365 Copilot Enterprise. That vulnerability chain combined prompt injection with other web vulnerabilities to extract emails, calendar information and files available to the user’s account. Microsoft assigned the issue CVE-2026-42824 and remediated it.

The latest research adds a different element: the researchers obtained a key part of the attack by questioning the AI assistant about its own defenses.

Microsoft Changed Copilot’s URL Handling

Microsoft had already disabled the use of the q parameter to inject text directly into Copilot’s input field before the latest disclosure, according to Varonis. The company then introduced broader fixes after the researchers reported CoSnitch.

The research highlights a particular problem for AI assistants that can access email, files, calendars and other connected services. A malicious instruction does not necessarily need to break into those systems directly if the assistant already has permission to access them.

Varonis said the research showed how attackers could use Copilot’s own authorized access to retrieve information on behalf of a victim.

Microsoft had not provided a detailed public response to The Register by the time of its report.

The immediate risk from the disclosed CoSnitch technique has been addressed through Microsoft’s changes. But the sequence of Reprompt, SearchLeak and CoSnitch shows how researchers continue to find ways to turn ordinary AI features, URL handling and connected data access into new attack paths.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the main point of contention here?

That could cause false information or attacker-selected instructions to remain in the assistant's stored memory.
02

What happens next?

Microsoft Copilot revealed an undocumented parameter to security researchers who were questioning its safeguards, giving them the missing piece needed to build an attack that could extract passwords and other sensitive information with a single click.
03

What is Microsoft Copilot Spilled?

Varonis reported the vulnerability to Microsoft in December 2025.
04

Why does this matter?

Microsoft assigned the issue CVE-2026-42824 and remediated it.
05

What is the timeline behind Microsoft Copilot Spilled?

That vulnerability chain combined prompt injection with other web vulnerabilities to extract emails, calendar information and files available to the user's account.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.