First Zero-Click AI Vulnerability "EchoLeak" Discovered in Microsoft 365 Copilot

Reviewed byNidhi Govil

9 Sources

Researchers uncover a critical zero-click AI vulnerability in Microsoft 365 Copilot, allowing attackers to exfiltrate sensitive data without user interaction. The flaw, dubbed "EchoLeak," highlights new security risks in AI-integrated systems.

Discovery of EchoLeak: A Zero-Click AI Vulnerability

In a groundbreaking discovery, researchers at Aim Labs have uncovered the first known zero-click artificial intelligence (AI) vulnerability, dubbed "EchoLeak." This critical flaw, identified in January 2025, affects Microsoft 365 Copilot, an AI assistant integrated into various Office applications 1.

Understanding the Vulnerability

EchoLeak is classified as an "LLM Scope Violation," a new class of vulnerabilities that can cause large language models (LLMs) to leak privileged internal data without user intent or interaction 2. The attack exploits the Retrieval-Augmented Generation (RAG) engine used by Copilot, allowing attackers to exfiltrate sensitive information from a user's context silently.

Source: Bleeping Computer

Source: Bleeping Computer

Attack Mechanism

The attack begins with a malicious email containing a hidden prompt injection, crafted to instruct the LLM to extract and exfiltrate sensitive internal data. This email, formatted to look like a typical business document, bypasses Microsoft's XPIA (cross-prompt injection attack) classifier protections 1.

When a user later interacts with Copilot, the RAG engine retrieves the malicious email due to its apparent relevance. The injected prompt then "tricks" the LLM into pulling sensitive data and inserting it into a crafted link or image 3.

Source: The Hacker News

Source: The Hacker News

Exploitation and Data Exfiltration

Aim Labs discovered that certain markdown image formats cause the browser to automatically request the image, sending the URL (including embedded data) to the attacker's server. While Microsoft's Content Security Policy (CSP) blocks most external domains, Microsoft Teams and SharePoint URLs are trusted and can be abused to exfiltrate data without issue 1.

Microsoft's Response and Mitigation

Microsoft assigned the vulnerability the identifier CVE-2025-32711, rating it critical with a CVSS score of 9.3 out of 10 4. The company addressed the issue server-side in May 2025, requiring no action from users. Microsoft stated that there is no evidence of real-world exploitation, and no customers were impacted 2.

Implications for AI Security

The discovery of EchoLeak has significant implications for AI security, particularly for NATO, government, defense, healthcare, and enterprises using AI assistants. Ensar Seker, CISO at SOCRadar, warns that "attackers no longer need to compromise user credentials or rely on phishing. They can manipulate a trusted AI interface directly" 5.

Source: Benzinga

Source: Benzinga

Future Concerns and Mitigations

As AI integration deepens in business workflows, experts warn that traditional defenses may be overwhelmed. Tim Erlin, a security strategist at Wallarm, noted that such vulnerabilities were "bound to happen" given the expanding AI attack surface 5.

To mitigate similar risks, enterprises are advised to:

  1. Strengthen prompt injection filters
  2. Implement granular input scoping
  3. Apply post-processing filters on LLM output
  4. Configure RAG engines to exclude external communications

Conclusion

The EchoLeak vulnerability serves as a wake-up call for the AI industry, highlighting the need for robust security measures in AI-integrated systems. As AI assistants become more prevalent, addressing these vulnerabilities will be crucial to maintain trust and security in AI technologies.

Explore today's top stories

Capgemini Acquires WNS for $3.3 Billion to Boost AI-Powered Intelligent Operations

French tech giant Capgemini agrees to acquire US-listed WNS Holdings for $3.3 billion, aiming to strengthen its position in AI-powered intelligent operations and expand its presence in the US market.

euronews logoSilicon Republic logoAnalytics India Magazine logo

10 Sources

Business and Economy

6 hrs ago

Capgemini Acquires WNS for $3.3 Billion to Boost AI-Powered

Google DeepMind's Isomorphic Labs Nears Human Trials for AI-Designed Drugs

Isomorphic Labs, a subsidiary of Alphabet, is preparing to begin human trials for drugs developed using artificial intelligence, potentially revolutionizing the pharmaceutical industry.

Fortune logoBenzinga logoDigit logo

3 Sources

Science and Research

14 hrs ago

Google DeepMind's Isomorphic Labs Nears Human Trials for

BRICS Nations to Advocate for AI Data Protection and Fair Compensation

BRICS leaders are set to call for protections against unauthorized AI use, addressing concerns over data collection and fair payment mechanisms during their summit in Rio de Janeiro.

Reuters logoU.S. News & World Report logoMarket Screener logo

3 Sources

Policy and Regulation

22 hrs ago

BRICS Nations to Advocate for AI Data Protection and Fair

Huawei's AI Lab Refutes Accusations of Copying Alibaba's Model in Pangu Pro Development

Huawei's AI research division, Noah Ark Lab, denies allegations that its Pangu Pro large language model copied elements from Alibaba's Qwen model, asserting independent development and adherence to open-source practices.

Bloomberg Business logoReuters logoEconomic Times logo

3 Sources

Technology

6 hrs ago

Huawei's AI Lab Refutes Accusations of Copying Alibaba's

Samsung's Q2 Profit Expected to Plunge 39% Amid AI Chip Supply Challenges

Samsung Electronics is forecasted to report a significant drop in Q2 operating profit due to delays in supplying advanced memory chips to AI leader Nvidia, highlighting the company's struggles in the competitive AI chip market.

Reuters logoMarket Screener logo

2 Sources

Business and Economy

14 hrs ago

Samsung's Q2 Profit Expected to Plunge 39% Amid AI Chip
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo