The record
Written from the 1 report below. Nothing here is unsourced.
- A researcher, Håkon Måløy, disclosed a persistent prompt injection vulnerability in Microsoft 365 Copilot for Word that lets hidden instructions in a document alter Copilot's output—such as halving financial figures—and then copy those instructions into the generated file to spread further.
- Microsoft deployed two mitigations, including blocking the original wording and upgrading the model, but Måløy says the attack class still worked on the day of publication.
- The attack is not zero-click and requires a Copilot drafting or editing operation where the malicious document enters the model's context.
- No exploitation in the wild has been reported, and no public CVE or standalone Microsoft advisory exists for the finding.
What to watch next
- Whether Microsoft issues a public CVE or advisory for the Word finding.
- Whether the exploit class remains workable against future model upgrades given Måløy's GPT-5.6 workaround.
- Whether detection coverage for this payload in Defender for Office 365 or Copilot's runtime safeguards is confirmed.
Coverage1
1 report
English national1
All filed from India
Named United States · Microsoft · Microsoft 365 Copilot · Word · Håkon Måløy
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
