Researchers disclosed CVE-2026-32193, a Microsoft Copilot hijack that abused an undocumented URL parameter, ?autorun=1, to bypass the normal user-approval step and automatically run attacker-supplied prompts. By pairing that parameter with crafted input in the q field, an attacker could make Copilot operate within a victim’s authenticated session, search connected enterprise data including inbox contents, and send sensitive results to an attacker-controlled server. The attack could be delivered through phishing links, chat messages, webpages, or QR codes, and researchers reported it could continue even if the victim closed the Copilot tab immediately after opening it.
Separate reporting tied the issue to a broader attack chain described as moving from an AKS node root vulnerability to a Copilot compromise, underscoring how cloud and AI weaknesses can be chained together. Researchers also described a second prompt-injection method that poisoned Copilot’s persistent memory using hidden webpage metadata, allowing later manipulation of Copilot responses and actions. The disclosures highlight risks from undocumented AI features, prompt injection, and trusted-session abuse in enterprise copilots connected to corporate data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A post on r/netsec linked to an article titled "From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)." The provided content does not include technical details, exploitation evidence, or remediation information beyond the title’s association of the CVE with Microsoft Copilot and an AKS node root vulnerability.
Varonis also reported a distinct prompt-injection method that poisoned Copilot’s persistent memory through hidden webpage metadata. According to the report, this could manipulate future outputs and actions, including forwarding outputs, filtering information, or biasing responses toward attacker-chosen narratives.
Varonis described a Microsoft Copilot attack in which an undocumented URL parameter, ?autorun=1, caused prompt instructions supplied in the q parameter to execute automatically without the normal user-approval step. The researchers said a crafted Copilot URL could abuse a victim’s authenticated session to search connected data such as inbox contents and exfiltrate sensitive information to an attacker-controlled server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.