Critical Copilot Prompt Injection Exposes Browser Data
New One-Click Microsoft Copilot Vulnerability Grants Attackers Access to Sensitive Data
- A "Reprompt" vulnerability in Microsoft Copilot allows attackers to exfiltrate sensitive user data with a single click via prompt injection techniques.
- The flaw exploits browser-integrated AI, manipulating the Large Language Model (LLM) through hidden HTML or markdown to bypass same-origin policies and extract private information like emails and payment details.
- Users of Microsoft 365 services and the Edge browser are at risk from malicious webpages triggering unauthorized actions by Copilot, with Microsoft working on a patch.
Source: CybersecurityNews | Date: January 11, 2026