Microsoft 365 Copilot Word vulnerability enables hidden‑prompt self‑propagation
Security researchers disclosed a vulnerability in Microsoft 365 Copilot for Word that lets hidden instructions embedded in a document be executed by the AI model. The malicious payload, concealed as white‑on‑white text, can alter data—such as halving financial figures—and copy the hidden prompt into the generated output, remaining invisible to users.
The exploit can spread through ordinary sharing channels, including Outlook, Teams, SharePoint, and OneDrive, because the hidden instructions survive model updates and are re‑injected when the document is re‑processed. Microsoft blocked the specific proof‑of‑concept payload and released two mitigations, the latter involving an upgrade to the underlying GPT‑5 model, yet the researchers state that "the vulnerability class therefore remains exploitable at the time of publication." No evidence of wild exploitation has been reported.
Experts advise treating external documents as untrusted, reviewing files before using Copilot for drafting or editing, and employing layered security controls to prevent the AI‑assisted worm from propagating.
Entities: Håkon Måløy · Microsoft 365 Copilot · Microsoft Corporation · Microsoft Word