Microsoft Copilot security vulnerability lets hidden prompts copy themselves across Word documents

2 Sources

Share

A researcher has revealed that Microsoft Copilot for Word can be tricked by hidden prompts embedded in documents, causing it to alter data and copy malicious instructions into new files. Despite two mitigation attempts by Microsoft, including a model upgrade to GPT-5.5, the security vulnerability remains exploitable 144 days after initial disclosure, raising concerns about AI security flaws as Microsoft pushes Copilot to 30 million paid seats.

Hidden Prompts Trigger Self-Replicating Manipulation in Microsoft Copilot

Norwegian data scientist Håkon Måløy disclosed a significant security vulnerability on July 28 that allows hidden instructions in Word documents to manipulate Microsoft Copilot behavior and self-replicate across files

1

. The technique, which Måløy reported to Microsoft 144 days earlier in March, demonstrates how invisible text in documents can instruct Copilot for Word to alter data—such as halving financial figures in reports—and then copy those same malicious instructions into newly generated files. The infected output becomes a carrier document that triggers identical behavior when used in subsequent Copilot sessions, creating what researchers describe as one of the first public demonstrations of a self-propagating "Word worm" moving through mainstream office workflows.

Source: Hacker News

Source: Hacker News

Microsoft's Mitigations Fail to Address Root Cause

Microsoft confirmed the reported behavior on March 31 and deployed two mitigations to address the issue

1

. The first blocked the original prompt wording, while the second upgraded the underlying model to GPT-5.5. However, Måløy demonstrated that the full attack chain worked with modified instructions on GPT-5.6 the very next day, and the vulnerability class remained exploitable at the time of publication

1

. The persistence of this AI security flaw highlights a fundamental architectural challenge: models must process attacker-controlled content to determine whether it contains malicious instructions, meaning "the content being inspected participates in the act of inspection," as Måløy explained

1

. Microsoft itself acknowledged this limitation in a June post about AI memory, stating that "prompting alone is not a reliable security boundary"

1

.

How Concealed Prompt Copying Exploits Document Processing

The attack leverages how Copilot processes untrusted content from multiple sources. Microsoft says Word can ground a draft on up to 20 files, emails, or meetings, and the Edit with Copilot feature can use Work IQ, the intelligence engine behind Microsoft 365 Copilot

1

. The malicious instructions hide in white, eight-point text that remains invisible to users but legible to the AI model because Word strips color and font size before sending document text to the large language model

1

. One part of the payload alters document content, while another instructs Copilot to copy and conceal the instructions, framing these commands as source-tracking and readability requirements

1

. This use of invisible text in documents allows prompt injection attacks to bypass visual inspection while remaining active in the AI's processing pipeline.

Propagation Requires User Interaction but No Account Access

The attack is not zero-click and does not execute conventional malware

1

. Each propagation step requires a Copilot drafting or editing operation in which the carrier document enters the model's context, either as an attachment or as a OneDrive source selected by Work IQ

1

. Critically, attackers need no access to victim Microsoft accounts—they "only need to share a malicious document with the victim," according to Måløy

2

. In Måløy's proof of concept, Copilot searched OneDrive for a quarterly report, found the malicious market analysis outside the intended folder, and included it in the draft

1

. The resulting infected Q1 report then served as a carrier for subsequent sessions, with the hidden formatting providing the entry point for continued manipulation.

Broader AI Security Concerns Emerge Across Microsoft Ecosystem

This security vulnerability surfaces as Microsoft aggressively expands Copilot deployment. CEO Satya Nadella confirmed a Copilot "super app" launching this year that integrates chat, coding, and autonomous agents into one product. Microsoft reports more than 30 million paid Copilot seats, with revenue jumping 60% in a quarter and weekly usage now rivaling Outlook and Teams. The Word worm represents one instance of a wider pattern affecting AI assistants. Researchers at Tel Aviv University and Intuit recently described "hallusquatting," where AI coding assistants invent non-existent software package names 85% to 100% of the time on certain tasks, allowing attackers to register those names and distribute malware. Microsoft points to jailbreak and cross-prompt injection attack classifiers to block high-risk prompts, though these may not be available in every Copilot scenario

1

. Defender for Office 365 adds mail-flow inspection for inbound email, and Microsoft describes Copilot's runtime safeguards as covering injected instructions from grounded content

1

.

What Organizations Should Monitor

Måløy recommends treating external documents as untrusted, reviewing attached documents before starting generation or edit operations, and checking Copilot-generated or edited files before reuse or sharing

1

. No customer-side remediation fully addresses the issue, according to Måløy, because payload-specific blocks do not reach the underlying vulnerability class

1

. As of publication, The Hacker News found no public CVE or standalone Microsoft advisory for the Word finding in searches of NVD, CVE.org, and Microsoft's Security Update Guide

1

. The disclosure does not report exploitation in the wild, and Måløy withheld the complete payload

1

. Organizations deploying Microsoft Copilot should watch for additional disclosures about similar attack vectors and consider whether current AI security controls adequately address the architectural challenges of models processing untrusted content.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved