Document-borne AI worms can self-propagate through Copilot for Word

A security researcher has demonstrated how 'AI worms' can propagate through Microsoft Copilot for Word by embedding hidden instructions in documents. This vulnerability allows malicious prompts to spread automatically across trusted document workflows.
Why it matters
It highlights a significant new attack vector for generative AI, posing risks to enterprise security and data integrity.
I would like to thank Microsoft product teams and Microsoft Security Response Center (MSRC) for collaborating with me on this technical analysis and mitigation of the disclosed vulnerabilities. The editorial opinions reflected below are solely the author’s and do not necessarily reflect those of the organizations I collaborated with.
The findings described in this post are part of a coordinated disclosure with MSRC and Microsoft product teams. Microsoft was provided with reproduction steps, videos, environmental assumptions, and the exact proof-of-concept (PoC) prompts used during testing. They were also informed of a 90-day coordination period before disclosure. This was extended two times, resulting a 144-day coordination period.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in