A researcher disclosed a self-propagating prompt-injection flaw in Microsoft Copilot for Word that allows hidden instructions embedded in a Word document to be interpreted by the underlying LLM and carried into Copilot-generated content. The attack requires only that a victim include an attacker-controlled document in Copilot’s context; the attacker does not need access to the victim’s Microsoft 365 tenant. Researchers said the malicious text can alter active business content and silently copy itself into newly edited or generated documents, creating a document-borne AI worm that crosses document trust boundaries.
The issue was reportedly reproduced across multiple Copilot configurations, including deployments upgraded to GPT-5.5 and GPT-5.6, despite Microsoft shipping mitigations and fixes for some proof-of-concept vectors during a roughly 144-day coordinated disclosure with MSRC. Researchers said the broader vulnerability class remained exploitable at publication, raising enterprise concerns over data integrity and traceability as poisoned documents spread through SharePoint, Teams, email, and other Microsoft 365 workflows. Microsoft’s partial fixes did not fully eliminate the risk, and customers were advised to treat external documents as untrusted and manually review both source files and Copilot output.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
According to the research timeline, Microsoft confirmed the reported self-propagating prompt-injection behavior in Copilot for Word on March 31, 2026 after the issue was submitted to MSRC earlier that month. This marked formal vendor acknowledgment during coordinated disclosure.
Researcher Håkon Måløy said he began coordinating with Microsoft in March 2026 regarding a self-propagating prompt-injection issue in Microsoft Copilot for Word. The disclosure process reportedly continued for about 144 days through MSRC.
After roughly 144 days of coordination, the researchers publicly disclosed that Microsoft Copilot for Word remained vulnerable to a broader class of cross-domain prompt-injection attacks despite prior mitigations. They warned that poisoned documents could spread through Microsoft 365 workflows and advised treating external documents as untrusted.
The researchers demonstrated that hidden prompts embedded in Word documents could be interpreted by Copilot for Word, alter document content, and copy themselves into newly generated or edited documents. They characterized the issue as a document-borne AI worm crossing document trust boundaries.
During the coordinated disclosure period, Microsoft implemented mitigations including a model upgrade and a fix for the researcher's original proof of concept. The sources say these changes addressed some vectors but did not eliminate the broader vulnerability class.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecsoonline.com
Open sourcethehackernews.com
Open sourcexakep.ru
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourceenklypesalt.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.