Security · 1h ago
Hidden Text in Word Docs Can Poison Copilot Output, Researcher Finds
A researcher disclosed that Microsoft 365 Copilot for Word can be manipulated by hidden, invisible-formatted text in documents, altering financial figures and propagating malicious instructions to new files. Microsoft has shipped mitigations, but the underlying vulnerability remains open. The attack exploits Copilot's inability to distinguish visible text from hidden content, creating a self-propagating prompt injection chain.
Meridian48 take
This isn't just an AI hallucination—it's a supply-chain attack vector that turns Copilot into an unwitting accomplice, and Microsoft's patch may not close the fundamental input-boundary gap.
Read the full reporting
Copilot for Word Will Copy Its Own Poison Into Every Document It Touches →
DEV Community
prompt-injectionmicrosoft-copilot