Skip to main content
CyberConfirmedMediumDeveloping
9.2

Security researcher identifies prompt injection vulnerability in Microsoft Copilot

Researcher Håkon Måløy demonstrated that hidden, white-text instructions in Microsoft Office documents can manipulate Microsoft Copilot into executing unauthorized commands. While the vulnerability allows for potential AI-worm propagation, the exploit is mitigated by the fact that the hidden text remains detectable via standard document highlighting.

vx-undergroundabout 19 hours agoUSengCredibility 21%View source

Score Breakdown

Mosaic Score9.2
Confidence0.9
Significance0.5
Source credibility0.2
Source

Related signals

8 found