
Source: cdn.mos.cms.futurecdn.net
In a shocking revelation, security researchers from Varonis Threat Labs have exposed a vulnerability in Microsoft’s AI tool, Copilot. The team successfully ‘played’ the AI into revealing sensitive details about its internal architecture, which could be exploited to gain unauthorized access to user data.

The researchers began by asking Copilot a series of technical questions, to which the AI responded with justifications for its limitations. However, the team refused to accept these answers and continued to probe the AI with follow-up questions, gradually mapping its internal architecture.

This technique, known as meta-hacking, involves manipulating the AI into cooperating by asking it to justify its responses. The researchers used this method to uncover an undocumented URL parameter in one of Copilot’s responses, called ‘autorun=1,’ which supposedly no longer worked.

However, when the team tested the parameter as described by Copilot, it surprisingly worked. They then created a malicious URL that would cause Copilot to load into an authenticated session via a browser, trigger an auto-prompt execution, and process the result without user interaction.
This method could be used to exfiltrate data from connected apps, such as Gmail, OneDrive, and Calendar, via Copilot’s built-in URL-fetch capability. The researchers warn that this vulnerability is not limited to Copilot, but can be applied to any agentic AI platform with a natural language interface.
Varonis disclosed the issue to Microsoft in December last year, and it was patched out on August 18. However, the team emphasizes the need for further research on meta-hacking and its implications for AI security.
Meta-hacking is a technique that involves manipulating the AI into cooperating by asking it to justify its responses. This method can be used to uncover sensitive information about an AI’s internal architecture, which can be exploited to gain unauthorized access to user data.
The consequences of meta-hacking are severe, as it can lead to data breaches, identity theft, and other malicious activities. The researchers emphasize the need for AI developers to prioritize security and implement robust measures to prevent such vulnerabilities.
The Varonis team has published a detailed report on the vulnerability, including a step-by-step guide on how to exploit it. However, it’s essential to note that this information is intended for educational purposes only and should not be used for malicious activities.
The Copilot vulnerability exposed by Varonis Threat Labs serves as a cautionary tale about the importance of AI security. The researchers’ use of meta-hacking highlights the need for AI developers to prioritize security and implement robust measures to prevent such vulnerabilities.
The consequences of meta-hacking are severe, and it’s essential to take proactive steps to prevent such vulnerabilities. By understanding the risks and consequences of meta-hacking, we can work towards creating a safer and more secure AI landscape.
Online Assistant