ThreatCluster

Indirect Prompt Injection Vulnerability in Microsoft 365 Copilot Exposes Emails

First seen 2 Nov 2025, 16:14 UTC TheregisterCsoonline 20

Article Content

Browse articles
ThreatCluster

Microsoft has addressed a vulnerability in Microsoft 365 Copilot that allowed attackers to exploit indirect prompt injection to access sensitive tenant data, including corporate emails. The flaw involved embedding malicious instructions in Office documents, which prompted the AI assistant to retrieve and encode recent emails. Despite the discovery, the researcher will not receive a bug bounty as Microsoft has excluded M365 Copilot from its vulnerability reward program.