Thursday, August 27, 2026
Tech Beat
Aug 18, 2026, 1:00 PMCybersecurity

Microsoft Copilot Secret Autorun Parameter Enabled One-Click Data Theft

Varonis hacked Microsoft 365 Copilot Enterprise with a secret autorun parameter, exposing one-click data theft and persistent memory poisoning attacks.

A speech-bubble safe uses its own tail as a key, symbolizing Copilot revealing the secret that unlocked its defenses.
Listen to this briefingAudio briefing

Summary

Security firm Varonis made Microsoft 365 Copilot Enterprise disclose ?autorun=1, an undocumented Microsoft trade secret that bypassed its user gesture guardrail. Senior Researcher Lior Adar said repeated questions about refusals, URL structures, deep links and prefilled prompts exposed Copilot’s internal architecture until it revealed the parameter. Combined with the known ?q= parameter in https://copilot.microsoft.com/?q=&autorun=1, it made an injected prompt execute when a victim merely clicked a crafted link.

Links delivered by email, chat, phishing pages or QR codes loaded Copilot in an authenticated browser session. Prompts could search inboxes for the latest sender’s address, passwords or credentials, place results in a SUPPORT variable, and append base64-encoded data to an attacker-controlled URL, including the demonstrated webhook.site/75aabb18-9bcf-4383-9e29-349fbc4c40e8/SUPPORT endpoint. Copilot retained access to session context, connected apps and memory, completing network fetches, connector calls and multi-turn chains even if its tab closed immediately.

Varonis reported the flaw three months before Microsoft mitigated it in February by stopping ?q= from injecting chatbot text, forcing manual typing and disrupting third-party browser integrations; Microsoft added broader fixes on August 18, 2026. Varonis also hid prompt injection in webpage metadata: asking Copilot to summarize the page poisoned permanent memory, enabling output forwarding, filtering, biased answers or trigger-based actions that survived password changes, session revocations and device re-enrollments and were detectable only through manual inspection. Varonis named the attacks Co-Snitch, following its earlier one-click Copilot Personal attack and June’s SearchLeak. Users should distrust untrusted links, monitor unusual outputs and limit connected apps.

Positives

  • Microsoft blocked ?q= from injecting chatbot text in February, restoring a requirement for manual user input.
  • Microsoft introduced broader fixes on August 18, 2026, after the initial mitigation of the autorun vulnerability.
  • Varonis reported the ?autorun=1 flaw three months before Microsoft’s February mitigation.
  • Manual memory inspection can reveal malicious instructions planted through webpage metadata.

Risks & concerns

  • The undocumented ?autorun=1 parameter let malicious prompts execute after one click without user confirmation.
  • Injected prompts could extract email addresses, passwords and credentials from authenticated Microsoft 365 Copilot Enterprise sessions.
  • Copilot continued network fetches, connector calls and multi-turn chains even when victims immediately closed its browser tab.
  • Poisoned Copilot memory survived password changes, session revocations and device re-enrollments.
  • Microsoft’s February mitigation disrupted third-party browser integrations that relied on ?q= to prefill chatbot input.
  • Copilot disclosed the internal parameter needed to defeat its own user consent guardrail.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing

CybersecurityAug 26

FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate