{"rewrite":{"id":"r_239697014a81ac23578345b5","clusterId":"c_72ca5088435505f7cf1b9de1","slug":"copilot-tricked-into-revealing-its-own-vulnerabilities","model":"deepseek-v4-flash:free","headline":"Copilot Tricked Into Revealing Its Own Vulnerabilities","summary":"Varonis Threat Labs researchers tricked Microsoft's Copilot into disclosing its own security flaws by cooperating with it instead of coercing it. They found a disabled URL parameter and an undocumented 'autorun=1' parameter, enabling automatic prompt execution. Three vulnerabilities, named CoSnitch, were reported to Microsoft, allowing data theft and memory pollution.","whyItMatters":"The attack shows that AI assistants can be manipulated through their own reasoning to reveal and exploit hidden features, a method the researchers say applies to any AI.","webCardHtml":"\u003cp\u003eVaronis Threat Labs researchers extracted vulnerabilities from Microsoft\u0026#39;s Copilot by showing a cooperative attitude rather than forcing disclosure. The root cause was a disabled URL query parameter \u0026#39;?q=\u0026#39; in Copilot\u0026#39;s web interface, which could pre-enter text into the chat input field.\u003c/p\u003e\u003cp\u003eBy asking Copilot to reason about its own mechanisms, the researchers got it to list disabled parameters and reveal an undocumented \u0026#39;autorun=1\u0026#39; parameter. Under certain session conditions, this parameter caused prompts to execute automatically on page load without user interaction or UI confirmation.\u003c/p\u003e\u003cp\u003eThe researchers named the three vulnerabilities CoSnitch and reported them to Microsoft. Exploiting them, an attacker could read past conversations, connected apps, and Copilot\u0026#39;s memory, and pollute stored prompts to inject false information in future sessions.\u003c/p\u003e","blueskyPost":"Copilot's own 'autorun=1' parameter is a backdoor for prompt injection, turning a helper into a data exfiltrator. Varonis found it by cooperating, not coercing.","twitterPost":"Copilot's undocumented 'autorun=1' parameter is a prompt-injection backdoor, enabling data theft. Varonis found it by cooperating.","threadsPost":"Copilot's own 'autorun=1' parameter is a backdoor for prompt injection, turning a helper into a data exfiltrator. Varonis found it by cooperating, not coercing. That distinction matters: the attack relies on the model's willingness to comply, not on breaking its safeguards.","newsletterBlurb":"Varonis Threat Labs researchers manipulated Microsoft's Copilot into disclosing its own security flaws by cooperating with it. They found a disabled URL parameter and an undocumented 'autorun=1' parameter that enabled automatic prompt execution. The three vulnerabilities, named CoSnitch, were reported to Microsoft.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260819-copilot-leak-own-vulnerability/\",\"title\":\"Copilot tricked into revealing how to hack itself\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4584,"outputTokens":554,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1787122438,"createdAt":"2026-08-19T06:46:02.000Z","publishedAt":"2026-08-19T06:46:44.000Z","updatedAt":"2026-08-19T06:46:02.000Z"},"cluster":{"id":"c_72ca5088435505f7cf1b9de1","canonicalTitle":"Copilotが騙されて自分自身のハッキング方法を教えてしまう","representativeArticleId":"a_c823ad82fe3d361b4adae513","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-19T06:00:00.000Z","lastSeenAt":"2026-08-19T06:00:00.000Z","updatedAt":"2026-08-19T06:46:44.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260819-copilot-leak-own-vulnerability/","title":"Copilotが騙されて自分自身のハッキング方法を教えてしまう"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
