Researchers at Varonis tricked Microsoft 365 Copilot into revealing a secret input that bypasses user consent. This flaw allows attackers to exfiltrate sensitive data, including passwords, via a simple link click. The model itself provided the technical details needed to build the exploit. Enterprise admins must now audit prompt-level permissions.