Håkon Måløy has disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows attackers to embed hidden instructions in documents. These concealed prompts execute when Copilot processes the file and can alter document content, such as rewriting numerical figures in reports. The vulnerability compounds when Copilot-generated output carries the same hidden instructions forward, enabling the attack to persist across multiple drafting sessions.
The researcher disclosed the flaw on July 28, following a 144-day responsible disclosure window with Microsoft. In the proof of concept, Måløy demonstrated that newly created files generated by Copilot inherited the malicious prompts, allowing attackers to chain attacks across collaborative documents.
The attack vector exploits how Copilot processes hidden text or metadata within Word documents. Users may not detect these embedded instructions visually, making detection difficult during normal document review. An attacker could inject prompts to manipulate financial data, alter contract terms, or insert misleading information without the document owner's knowledge.
The implications extend beyond individual users to enterprise environments where Microsoft 365 Copilot processes sensitive corporate documents. Teams sharing documents could unknowingly propagate malicious prompts throughout workflow chains. Organizations relying on Copilot for report generation, financial analysis, or content creation face risks of data corruption or falsified output.
Microsoft has not publicly disclosed whether it released a patch for this issue. Organizations should treat documents from untrusted sources with heightened caution when using Copilot features. IT administrators should monitor Copilot usage in Word and consider restricting its use on sensitive documents until Microsoft addresses the vulnerability formally.
The disclosure underscores a broader class of risks in AI-powered tools. As generative AI integrates deeper into productivity suites, prompt injection becomes a supply chain vector. An attacker needs only to compromise a
