Microsoft 365 Copilot Vulnerability Allows Data Theft via Indirect Prompt Injection
First seen 2 Dec 2025, 18:33 UTC
•
•21
Export
Article Content
Browse articles
Microsoft has patched a vulnerability in Microsoft 365 Copilot that allowed attackers to exploit indirect prompt injection to access sensitive corporate emails. The flaw was identified by security researcher Adam Logue, who reported that attackers could embed malicious instructions in Office documents, leading the AI assistant to retrieve and leak sensitive data. Microsoft determined that the Copilot tool is not eligible for their bug bounty program.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.