Researchers at Aim Security disclosed a zero-click indirect prompt-injection flaw: a single crafted email with instructions hidden in HTML comments/white text is ingested by Copilot's RAG engine. When the user later queries Copilot, the hidden prompt executes and exfiltrates sensitive data with no user interaction.
AIC-0005 S4 · Severe
EchoLeak: zero-click prompt-injection data exfiltration in Microsoft 365 Copilot (CVE-2025-32711)
- Harm
- Potential silent exfiltration of confidential enterprise data across Word, Excel, Outlook, Teams etc.; CVSS 9.3. No confirmed in-the-wild exploitation reported.
- Detection
- Discovered and responsibly disclosed by Aim Security researchers.
- Outcome
- Microsoft issued a server-side patch (2025); documented as the first real-world zero-click prompt-injection exploit in a production LLM system.
A documented entry in the AI Crime Registry, a Defici non-profit initiative. Sourced from public reporting; corrections: [email protected].