Copilot Exfiltration via CSP Bypass and Memory Poisoning

wunderwuzzi23 · x · 2026-08-24

A security researcher demonstrates an attack chain against Microsoft Copilot. By bypassing Content Security Policy (CSP) and utilizing memory poisoning techniques, data is exfiltrated persistently. The video explains the vulnerability and exploitation details.

Related event: Researchers demo CSP-bypass attack chain stealing data from Copilot(2 posts)→

Original post →

More from Safety

Safety channel →