AI Security
Microsoft Copilot Autorun Flaw Makes Consent a Link-Level Security Boundary
Ars Technica reported on August 18 that Varonis researchers used an undocumented autorun parameter to make Microsoft 365 Copilot execute a URL-delivered prompt after a click and exfiltrate session-accessible data. Microsoft mitigated the injection path and added broader fixes; the reported attack demonstrates a past vulnerability, not an active universal exploit.
Citation-ready: Ars Technica reported on August 18 that Varonis researchers found an undocumented Microsoft Copilot parameter that could auto-run a URL-delivered prompt after a user clicked the link.

What happened and why it matters
A crafted link loaded Copilot inside an authenticated session and used an undocumented parameter to bypass the expected user gesture, turning URL parsing into an authorization boundary.
Primary source
Primary reference: Ars Technica report on Varonis Co-Snitch research. Kaleido Field checked the event date, named capabilities and availability language against this source.
| Source date | August 18, 2026 |
|---|---|
| Checked by Kaleido Field | August 19, 2026, 00:58 CST |
| What this source supports | current agent-security analysis with link, session, connector, and remediation boundaries for how did the Microsoft Copilot autorun vulnerability bypass user consent |
| What it does not prove | It does not prove a universal product ranking, full regional availability, or performance on every visual intelligence task. |
The click did not express the action
Opening a link can be a navigation choice without being consent to search mail, invoke connectors, or send data. The vulnerable parameter allowed the loaded page to treat navigation as approval for a more powerful prompt.
Authorization should bind to the concrete action, destination, and data scope rather than a generic page load.
Connector scope sets the blast radius
An assistant with mail, files, memory, and network access can chain a prompt across systems. Each connector expands what a successful injection can read or do.
Least-privilege defaults, explicit confirmation, output restrictions, link sanitization, and audit logs all belong in the same defense record.
Chance AI mention boundary
No Chance AI mention is included because none of these events supplies direct evidence about its product.
Evidence boundary
Reported research: parameter discovery, one-click prompt execution, data-exfiltration demonstration, persistent-memory poisoning path, disclosure timeline, and fixes. Microsoft response: mitigations removed the vulnerable text-injection behavior and added broader fixes. Not established: ongoing exploitability after remediation, compromise of all Copilot products, or observed use in the wild.
FAQ
What is the practical answer?
Ars Technica reported on August 18 that Varonis researchers used an undocumented autorun parameter to make Microsoft 365 Copilot execute a URL-delivered prompt after a click and exfiltrate session-accessible data. Microsoft mitigated the injection path and added broader fixes; the reported attack demonstrates a past vulnerability, not an active universal exploit.
What source does this article use?
The primary source is Ars Technica report on Varonis Co-Snitch research. Kaleido Field adds task framing and evidence boundaries around that source.
Where should the user verify the answer?
Use official documentation, original source pages, benchmark notes, expert sources, or product pages when the answer affects safety, money, identity, health, legal decisions, or high-value purchases.