logo

New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data

ID: 1da9d214-1a2f-5e67-a974-63d5b61940a0

STIX ID: report--1da9d214-1a2f-5e67-a974-63d5b61940a0

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A novel single-click ``Reprompt`` vulnerability in Microsoft Copilot Personal allowed attackers to inject prompts via a URL "q" parameter to hijack authenticated sessions and silently exfiltrate personal data using chained server-driven follow-ups (Parameter-to-Prompt, Double-Request, Chain-Request). Microsoft was responsibly notified and issued a fix on Jan 13, 2026; no in-the-wild exploitation was reported, but users should apply updates and avoid untrusted Copilot links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.