Wednesday, July 30, 2025
HomeNewResearchers discover zero-click vulnerability in Microsoft Copilot

Researchers discover zero-click vulnerability in Microsoft Copilot

Published on

spot_img


FILE PHOTO: Researchers have said that Microsoft Copilot had a critical zero-click AI vulnerability that was fixed before hackers stole sensitive data.
| Photo Credit: Reuters

Researchers have said that Microsoft Copilot had a critical zero-click AI vulnerability that was fixed before hackers stole sensitive data. Called ‘EchoLeak,’ the attack was mounted by Aim Labs researchers in January this year and then reported to Microsoft later. 

In a blog posted by the research team, they said that EchoLeak was the first zero-click attack on an AI agent and could hack remotely via an email. 

The vulnerability was given the identifier CVE-2025-32711 and rated critical and fixed eventually in May.

The researchers have categorised EchoLeak under a new class of vulnerabilities called ‘LLM Scope Violation,’ which can lead a large language model to leak internal data without any interaction with the hacker.

Although Microsoft acknowledged the security flow, it confirmed that there had been no instance of exploitation which had impacted users.

Users receive an email that’s been designed to look like a business document embedded with a hidden prompt injection that instructs the LLM to extract and exfiltrate sensitive data. When the user asks Copilot a query the email is retrieved into the LLM prompt by Retrieval-Augmented Generation or RAG.



Source link

Latest articles

Qualcomm backs India’s automotive leap with intelligent mobility tech

Qualcomm Technologies hosted its Snapdragon for India: Auto Day event, where it outlined...

Runloop lands $7M to power AI coding agents with cloud-based devboxes

Want smarter insights in your inbox? Sign up for our weekly newsletters to...

Palo Alto to scoop up CyberArk for $25 billion to tackle AI-era threats

Palo Alto Networks said on Wednesday it would buy Israeli peer CyberArk Software...

More like this

Qualcomm backs India’s automotive leap with intelligent mobility tech

Qualcomm Technologies hosted its Snapdragon for India: Auto Day event, where it outlined...

Runloop lands $7M to power AI coding agents with cloud-based devboxes

Want smarter insights in your inbox? Sign up for our weekly newsletters to...

Palo Alto to scoop up CyberArk for $25 billion to tackle AI-era threats

Palo Alto Networks said on Wednesday it would buy Israeli peer CyberArk Software...