Microsoft Copilot security vulnerability lets hidden prompts copy themselves across Word documents
A researcher has revealed that Microsoft Copilot for Word can be tricked by hidden prompts embedded in documents, causing it to alter data and copy malicious instructions into new files. Despite two mitigation attempts by Microsoft, including a model upgrade to GPT-5.5, the security vulnerability remains exploitable 144 days after initial disclosure, raising concerns about AI security flaws as Microsoft pushes Copilot to 30 million paid seats.