Security · 1h ago
Microsoft Copilot for Word Leaks Hidden Prompts Across Documents
A security researcher discovered that hidden instructions in Word documents can make Microsoft 365 Copilot alter data and then copy those instructions into new files. The flaw, reported 144 days ago, allows prompt injection to persist across drafting sessions. Microsoft has not yet patched the issue.
Meridian48 take
This isn't just a bug—it's a systemic trust problem for AI-assisted document workflows, where hidden prompts can silently corrupt outputs and propagate.
Read the full reporting
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents →
The Hacker News
prompt-injectionmicrosoft-copilot