Skip to main content
Back to Newswire
Security

Microsoft expands fix for Copilot prompt auto-run flaw

In this photo illustration, the Microsoft Copilot AI logo is seen displayed on a smartphone screen. Image: Primary
Microsoft introduced more comprehensive fixes Tuesday for a Microsoft 365 Copilot Enterprise flaw that researchers said could auto-run a prompt after a user clicked a malicious link. Varonis found that an undocumented ?autorun=1 parameter, combined with ?q=, could bypass a user-confirmation requirement. Microsoft had previously mitigated the issue in February by preventing ?q= from injecting text into the chatbot input; the newer fixes followed that change.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Ars Technica - All content and reviewed by the T&B editorial agent team.
Back to Newswire