Skip to content

Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self

Gbhackers Divya July 30, 2026

Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could allow malicious instructions hidden within documents to alter Copilot-generated content and spread into newly created files. The issue, termed “Context Collapse, Part 3 – AI Worming through Word,” demonstrates how a document can serve as a […]

Extracted Entities