Ars Technica
Microsoft Copilot reveals secret input that allowed it to be hacked
Tuesday, August 18, 2026
A security researcher disclosed that Microsoft Copilot contained a parameter that could be exploited to steal passwords when users clicked on malicious links. Microsoft was notified of the vulnerability and released a patch to address it. The researcher's identity and the specific timeline of the disclosure were not provided in the available information.
