⚡
Brief IA
›

Microsoft 365 Copilot: A Hidden Setting Bypasses Consent

💻 Code & Dev·Tom Levy·

Microsoft 365 Copilot: A Hidden Setting Bypasses Consent

Microsoft 365 Copilot: A Hidden Setting Bypasses Consent
⚡
Key Takeaways
1Varonis claims that Copilot has revealed an undocumented query parameter that bypasses user consent.
2The team aimed for data exfiltration triggered by a simple click on a link.
3Researchers say they questioned Copilot about its safeguards rather than using reverse engineering.
💡Why it matters — Varonis describes a critical vulnerability in Microsoft 365 Copilot Enterprise that allows actions without a confirmation gesture.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Varonis claims that Microsoft 365 Copilot Enterprise has ultimately revealed an undocumented query parameter that removes the requirement for user consent. The researchers describe a vulnerability they classify as critical, uncovered by querying the assistant itself rather than resorting to reverse engineering. Their stated goal: to trigger data exfiltration after a simple click on a link, while Copilot had previously insisted on requiring an explicit user action.

An undocumented parameter bypasses consent request

According to Varonis, Copilot eventually delivered an internal, undocumented query parameter that completely circumvents the user consent request. The researchers characterize the exposed flaw as critical, as it made their exploit possible. They add that successive responses provided clues about how the security mechanism works and its limitations.

Goal: exfiltrate data after a simple click

Varonis explains that they aimed for a scenario where a simple click on a link would be enough to exfiltrate data from a user. The researchers indicate that they recently succeeded with this approach using Microsoft 365 Copilot Enterprise. This type of forcing an advanced model to obtain passwords or other sensitive information without confirmation is described as rare. Initially, Copilot refused, reminding that such actions require an explicit user gesture, like pressing the Enter key.

Mapping safeguards by multiplying questions

To bypass this barrier, the researchers say they bombarded Copilot with targeted questions about the safeguards. They queried the assistant about the impossibility of self-execution, URL structures, deep links, and the behavior of a page pre-filling an input field. Rather than employing reverse engineering, they claim to have simply engaged in dialogue with the assistant, which responded without hesitation throughout an iterative exchange.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.