News

Security Flaw in Microsoft Copilot Exposed Password Theft Risk via Malicious Links

Security researchers have identified a significant vulnerability in Microsoft Copilot that could have allowed attackers to harvest user passwords through specially crafted links.

The flaw stemmed from a secret parameter embedded within Copilot's functionality. When a targeted user clicked on a malicious link designed by an attacker, the vulnerability could be triggered, potentially exposing sensitive credentials including passwords.

Microsoft has addressed this security issue following responsible disclosure by the researchers. Users of Microsoft Copilot are encouraged to ensure their installations are up to date and to exercise caution when clicking links, even those appearing within trusted applications.

This discovery highlights the ongoing security challenges facing AI-powered assistant tools as they become increasingly integrated into daily workflows. Security experts note that the expanding attack surface created by AI features requires continuous scrutiny and prompt patching of vulnerabilities.

Sources