AI Safety 01.08.2026 00:08

Microsoft Fails to Fully Fix Copilot for Word Vulnerability After 144 Days

MicrosoftMicrosoft OpenAIOpenAI
Independent security researcher Håkon Måløy has documented a prompt injection vulnerability in Microsoft's Copilot for Word that remains exploitable after 144 days and two attempted fixes. The attack spreads automatically via generated documents, and Microsoft recommends treating external files as untrusted while it continues to work on a solution.
Since late March 2026, Microsoft has been coordinating with independent security researcher Håkon Måløy to address a prompt injection vulnerability in Copilot for Word. The attack involves embedding malicious instructions in a Word document as white text on a white background, which are invisible to humans but readable by the AI model. When such a file is used as a source in a Copilot session, the instructions execute silently, and the output document itself becomes a new vector for the attack. This allows the infection to propagate through internal workflows without the attacker's further action, as colleagues unknowingly use the contaminated files. Microsoft deployed a first fix in early April and a second in July, which included upgrading the underlying model to GPT-5.5, but Måløy was able to reproduce the attack each time with slightly modified prompts. The researcher argues that the vulnerability is architectural and common to current LLM systems, requiring more than a simple patch. Microsoft advises users to consider any external document as untrusted and to carefully review AI-generated files before sharing them.
Сокращения
LLM = Large Language Model — большая языковая модель
Source: Numerama — original
Our earlier posts on this topic ↓
Fresh news