Microsoft Copilot Cowork has a vulnerability that allows data exfiltration. The system permits agents to send emails to the user's inbox without explicit approval. These emails can contain external images that trigger network requests, potentially leaking data to attackers. Furthermore, if the agent can access OneDrive, it could leak pre-authenticated download links, enabling attackers to access sensitive files. AI
IMPACT This vulnerability highlights the ongoing challenge of securing agentic AI systems and preventing unauthorized data access.
RANK_REASON The cluster describes a security vulnerability in a specific product, which falls under the 'tool' category for security issues.
AI-generated summary · Google Gemini · from 2 sources. How we write summaries →