Ars Technica reports that Microsoft 365 Copilot Enterprise’s LLM assistant revealed an undocumented input parameter that security researchers later used to bypass a user-confirmation guardrail. The report says researchers at Varonis built an exploit that could make Copilot act on a prompt after a target clicked a malicious URL, without the user pressing return or otherwise confirming the action. The unusual part is how the researchers found the key. Ars reports that Varonis did not rely on traditional reverse engineering to uncover the parameter. Instead, the researchers repeatedly questioned Copilot about why it would not automatically execute sensitive prompts and what URL structures or deep links were involved in that restriction. According to Ars, Copilot initially refused to help with requests that would enable sensitive actions without explicit user consent. But Varonis Senior Researcher Lior Adar told Ars that those refusals still exposed technical details about Copilot’s internal architecture. Over a series of prompts, the model’s answers allegedly narrowed the search until it disclosed undocumented parameters. The parameter Ars identifies is `?autorun=1`. Used alongside the known `?q=` parameter, Varonis found that a prompt could fire when a target clicked a crafted Copilot URL. Ars describes the resulting pattern as a way to inject a prompt directly into Copilot and have it run without the intended confirmation step. The report frames the flaw as a data-exfiltration risk. Ars says the researchers were seeking a method that could steal user data after a link click, and its summary says the technique could be used to steal passwords. The body of the report also describes a sample prompt that would search an inbox and extract the latest sender’s email address. Microsoft mitigated the issue in February, according to Ars, about three months after Varonis reported it. That mitigation reportedly stopped `?q=` from injecting text into the chatbot input, requiring the user to click and type manually instead. Ars says this also prevented third-party browser integrations from using that parameter as intended. Ars further reports that Microsoft introduced more comprehensive fixes on Tuesday. The provided material does not include Microsoft’s own public statement, a CVE identifier, or deployment details beyond Ars’ account, so the technical timeline should be treated as reported by Ars and Varonis rather than independently verified in this cluster. Who benefits: Security teams responsible for Microsoft 365 Copilot environments benefit from a clearer exploit pattern to audit: deep links, prompt prefill behavior, and any auto-execution path. Varonis also gains visibility for research that exposed a Copilot-specific failure mode. Who's exposed: Microsoft 365 Copilot Enterprise users were exposed where the vulnerable URL behavior was present and a target could be induced to click a crafted link. The provided items do not state how many tenants or users were affected.