importantSYS.SOURCE: The Hacker News• 2026-07-30T17:24:49+05:30
Microsoft Copilot for Word Vulnerability Allows Hidden Prompt Injection
A vulnerability in Microsoft Copilot for Word allows hidden prompts within documents to be copied into new files during drafting sessions, enabling potential malicious manipulation. Microsoft's mitigations did not fully resolve the issue, and the attack requires user interaction through Copilot's editing features.
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.
In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.
Måløy's
*** END OF TRANSMISSION ***