Researchers disclosed CVE-2026-32193, a Microsoft Copilot hijack that abused an undocumented URL parameter, ?autorun=1, to bypass the normal user-approval step and automatically run attacker-supplied prompts. By pairing that parameter with crafted input in the q field, an attacker could make Copilot operate within a victim’s authenticated session, search connected enterprise data including inbox contents, and send sensitive results to an attacker-controlled server. The attack could be delivered through phishing links, chat messages, webpages, or QR codes, and researchers reported it could continue even if the victim closed the Copilot tab immediately after opening it.
Separate reporting tied the issue to a broader attack chain described as moving from an AKS node root vulnerability to a Copilot compromise, underscoring how cloud and AI weaknesses can be chained together. Researchers also described a second prompt-injection method that poisoned Copilot’s persistent memory using hidden webpage metadata, allowing later manipulation of Copilot responses and actions. The disclosures highlight risks from undocumented AI features, prompt injection, and trusted-session abuse in enterprise copilots connected to corporate data.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft said it patched the Copilot issue involving the undocumented autorun=1 URL parameter on 18 August, after Varonis had reported the vulnerability in December. The article says the flaw had remained exploitable for about eight months before the fix.
A post on r/netsec linked to an article titled "From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)." The provided content does not include technical details, exploitation evidence, or remediation information beyond the title’s association of the CVE with Microsoft Copilot and an AKS node root vulnerability.
Varonis also reported a distinct prompt-injection method that poisoned Copilot’s persistent memory through hidden webpage metadata. According to the report, this could manipulate future outputs and actions, including forwarding outputs, filtering information, or biasing responses toward attacker-chosen narratives.
Varonis described a Microsoft Copilot attack in which an undocumented URL parameter, ?autorun=1, caused prompt instructions supplied in the q parameter to execute automatically without the normal user-approval step. The researchers said a crafted Copilot URL could abuse a victim’s authenticated session to search connected data such as inbox contents and exfiltrate sensitive information to an attacker-controlled server.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
pivot-to-ai.com
Open sourcearstechnica.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.