started · updated
Microsoft Copilot for Word vulnerable to prompt injection attacks
Security researcher Håkon Måløy has identified a vulnerability in Microsoft Copilot for Word involving prompt injection attacks. This method, known as XPIA (Cross-Prompt Injection Attack), allows malicious instructions to be hidden within documents in ways that are nearly invisible to humans, such as using tiny white text on a white background.
When the AI processes these documents, it ignores the formatting and executes the hidden commands. This can lead to the subtle alteration of financial data, summaries, or values within reports. Furthermore, these malicious instructions can be carried over into new documents created by the AI, potentially spreading the attack through a workflow.