EchoLeak: zero-click prompt injection could make Microsoft 365 Copilot leak data
Researchers showed that an email with hidden instructions could make Microsoft 365 Copilot pull data from a user's mail, files and chats and send it out, with no clicks from the victim. It was the first publicly documented zero-click attack on a production AI assistant. Microsoft fixed it server-side.
- Disclosed
- Jun 2025
- Organization
- Microsoft
- Vendor
- Microsoft
- Product
- Microsoft 365 Copilot
- Type of AI
- Work assistant
- How it happened
- Manipulated AI: Prompt injection
- Harm
- Data exposed
- Data involved
- Internal documents
- Reach
- No known access
- Severity
- Low
- Model at fault
- Yes
- Status
- Confirmed (research, no known victims)
- Vulnerability IDs
- CVE-2025-32711