Microsoft Copilot Vulnerability: Malicious Links Bypass Confirmation and Automatically Steal Emails and Credentials
Ars Technica reports Varonis found a Microsoft Copilot flaw: malicious links with ?autorun=1 and ?q= parameters bypass confirmation and auto-run prompts, using a five-step attack chain to steal Gmail emails and exfiltrate data via Base64, turning Copilot into a data theft channel.....