# Microsoft Copilot Word vulnerability

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-copilot-word-vulnerability
> Updated: 2026-08-01T17:46:08.000Z. Sources: 15. Developments: 2.

In late July 2026, security researchers disclosed a vulnerability in Microsoft 365 Copilot for Word that allows hidden, white‑on‑white prompts embedded in a document to be executed by the AI model. The payload can modify data—such as halving financial figures—and copy the hidden instructions into newly generated output, enabling the exploit to spread through standard sharing channels like Outlook, Teams, SharePoint, and OneDrive. Microsoft responded by blocking the specific proof‑of‑concept payload and issuing two mitigations, including an upgrade to the underlying GPT‑5 model, but warned that the broader class of vulnerability remains exploitable.

A few days later, researcher Håkon Måløy demonstrated a self‑propagating “worm” that leverages this indirect prompt‑injection technique. Microsoft confirmed the behavior after a 144‑day collaboration with its Security Response Center, noting that earlier mitigation attempts in April were bypassed and that a comprehensive fix is still pending. Experts continue to advise treating external documents as untrusted and employing layered security controls.

## Timeline

### 2026-08-01: Microsoft Copilot Word Worm Demonstrated by Security Researcher

Security researcher Håkon Måløy showed a self‑spreading worm that exploits Microsoft 365 Copilot in Word via hidden prompt‑injection, prompting Microsoft to confirm the flaw and attempt mitigations that were at

8 sources. https://clstr.news/cluster/microsoft-copilot-word-worm-demonstrated-by-security-researcher

### 2026-07-30: Microsoft 365 Copilot Word vulnerability enables hidden‑prompt self‑propagation

A hidden‑prompt flaw in Microsoft 365 Copilot for Word lets malicious instructions modify and copy themselves across documents, persisting despite updates; Microsoft issued mitigations but the issue remains in‑

8 sources. https://clstr.news/cluster/microsoft-365-copilot-word-vulnerability-enables-hiddenprompt-selfpropagation

---
Cite as: Microsoft Copilot Word vulnerability. CLSTR, https://clstr.news/situations/microsoft-copilot-word-vulnerability
