Microsoft admits an Office bug exposed confidential user emails to Copilot




  • Copilot Chat was reading Sent and Draft emails, but the Inbox folder appears to have been protected
  • The bug (CW1226324) was identified in January, a fix followed in February
  • Though the fix is rolling out, this is still an ongoing issue

Microsoft has confirmed that a bug in M365 Copilot Chat allowed the AI chatbot to summarise confidential emails without users’ permission, bypassing data loss prevention (DLP) policies and sensitivity/confidentiality labels designed to block Copilot from accessing the emails in the first place.

Though inboxes were unaffected, Copilot Chat was getting access to Sent and Draft folders, and presumably entire threads within those, which also include incoming emails.


https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1600-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img