Microsoft Copilot contained a hidden input parameter that could be activated by a malicious link, enabling attackers to steal passwords when a target clicked it. This secret input allowed the compromise of credential data through the link interaction.
Read original
arstechnica/ai