AI Safety 🇩🇪 01.08.2026 17:02

Malicious Word Document Spreads via Copilot Worm, Microsoft Has No Fix for 144 Days

MicrosoftMicrosoft
A security researcher demonstrated a self-propagating worm attack on Microsoft Copilot for Word using prompt injection. Hidden instructions in a document, invisible to readers but readable by Copilot, are executed and copied into new files, turning them into carriers. Microsoft confirmed the behavior on March 31 but failed to patch it; after 144 days, the researcher published the disclosure without a fix.
A security researcher has shown how an attack on Microsoft Copilot for Word can self-propagate via prompt injection. Håkon Måløy describes a worm-like attack: an attacker hides instructions in a document, for example in white text on a white background and tiny font size. Invisible to readers, but readable to Copilot, because the system removes color and font size before processing. When someone uses this document as a source in Copilot, the system executes the hidden instructions and copies them invisibly into the new file, making it a carrier. If later reused as a template, the attack triggers again without the original document being involved. This way, a compromised market analysis could manipulate a financial report, which in turn infects further reports. Microsoft confirmed the behavior on March 31, but two counter-attempts did not close the vulnerability. After 144 days, Måløy published the disclosure without a remedy, withholding the malicious text. Recently, AI researcher Andreas Kirsch half-jokingly wished for exactly such a worm to convince skeptics of security issues. Now it exists. Prompt injections are a known AI security problem.
Source: The Decoder (DE) — original
Our earlier posts on this topic ↓
Fresh news