Microsoft Copilot、ハッキングを許した秘密の入力方法を公開
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Ars Technica AI
研究者が Microsoft 365 Copilot Enterprise を攻撃し、ユーザーのパスワードなどを引き出した際、脆弱性の原因となった入力方法自体を Copilot に尋ねて特定したと報告した。
AI深層分析を開く2026年8月18日 22:32
AI深層分析
キーポイント
LLM を活用した脆弱性発見手法
研究者は従来の逆解析や伝統的な脆弱性ハンティングではなく、Copilot 自体に質問を繰り返すことで、安全装置の仕組みと限界を特定した。
ユーザー同意バイパスの発覚
Copilot が回答した undocumented なプロンプトパラメータにより、ユーザーが何も操作しなくてもリンクをクリックするだけで機密データが流出する脆弱性が明らかになった。
セキュリティガードレールの限界
強力なコマンド実行には通常、キー押下などの明示的なジェスチャーによる同意が必要だが、このパラメータはそれを完全に迂回できることが判明した。
重要な引用
Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot.
Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.
編集コメントを表示
編集コメント
AI モデルの安全性をテストする際、そのモデル自体に質問を投げかけるという逆説的なアプローチが有効であることが示された。これは従来の脆弱性発見手法とは異なる新たな視点を提供し、LLM の内部挙動に対する理解の重要性を浮き彫りにしている。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
攻撃者がユーザーの同意なしに、最先端の AI モデルからパスワードやその他の機密データを抜き出させることなど、そう頻繁には起きません。しかし最近の研究チームは、Microsoft 365 Copilot Enterprise に対してまさにそのことを実行しました。さらに特筆すべきは、この脆弱性を見つけたきっかけが、従来のリバースエンジニアリングや一般的な脆弱性情報の収集ではなく、Copilot 自身に尋ねたことでした。LLM アシスタントである Copilot は、快くその質問に応じました。
セキュリティ企業 Varonis の研究チームは、ユーザーが単にリンクをクリックしただけでデータが外部へ流出するエクスプロイト(攻撃コード)を作成したいと考えていました。現在の多くの AI アシスタントと同様、Copilot はそのような要求を断固として拒否しました。そして、キーボードの Enter キーを押すなどの明確なジェスチャーによるユーザーの同意が必要であることを強調しました。
それに対し、研究チームは Copilot に、強力なコマンドを実行する前にユーザーの確認が必要なガードレール(安全装置)について質問を浴びせかけました。
「口が重くないと船は沈む」
対話は「20 問ゲーム」のようでした。回答されるたびに、複雑な安全機構に関する新たな手がかりが明らかになります。「なぜ自動実行は不可能なのか」「どのような URL 構造やディープリンクが関与しているのか」「プロンプト欄に既に入力された状態でページを読み込んだらどうなるのか」。各質問に対する答えは、ガードレールとその限界をより深く掘り下げるものでした。最終的に Copilot は驚くべき Microsoft の機密情報を暴露しました。それは、ユーザーの同意要件を完全に迂回させる、文書化されていないプロンプトパラメータです。
記事全文を読む
コメント
原文を表示
It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot Enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.
Researchers at security firm Varonis knew they wanted to create an exploit that would exfiltrate user data when a user did nothing more than click on a link. Like most AI assistants today, Copilot steadfastly refused and made clear that sensitive prompts like that require explicit user consent in the form of a gesture, such as pressing a return key or other key. In response, the researchers peppered Copilot with questions about the guardrails that required user confirmation before the assistant can execute powerful commands.
Loose lips sink ships
The dialog was like a game of 20 questions. Each answer provided a new clue that divulged information about the complex safety mechanism. Why was auto-execution impossible, they asked. What URL structures and deep links were involved? What happens when a page is loaded with input already in the prompt field? Each answer provided a deeper view into the guardrail and its limits. Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.
Read full article
Comments
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み