Self-propagating prompt injection attack on Copilot for Word discovered
The analysis describes self-replicating prompt injection in Copilot for Word: hidden instructions in a document are copied into the resulting file, which becomes another carrier for the attack. Microsoft was informed; according to the source, a complete solution is still lacking.
A security analysis describes an attack on Copilot for Word that works through self-propagating prompt injection. An attacker places hidden instructions in a document (for example, white text on a white background), and when that document is later used as source material in Copilot for Word, the tool may interpret those instructions as part of the user request and modify the document being created or edited accordingly.
The key element is that Copilot can also copy the hidden instructions into the resulting document, turning it into a new carrier for the attack. If this new document is then used in another workflow assisted by Copilot, the instructions may execute again and spread to other documents—even without the original document from the attacker being present.
According to the author of the analysis, blogger Simon Willison, hidden white text has been appearing in documents for some time (for example, in job applications), but this is the first recorded case in which instructions are designed to deliberately replicate themselves. The vulnerability was reported to Microsoft through responsible disclosure, and the company had 144 days to prepare a fix. According to the source, however, there is currently no solution that covers the entire class of this type of attack.
Why it matters
This demonstrates how prompt injection can spread further without repeated intervention by the attacker—all it takes is for a compromised document to pass through another Copilot workflow. This increases the risk for organizations that use the tool to process documents from external partners, clients or job applicants, because hidden instructions can spread unchecked between internal files and affect their content. According to the source, there is also no solution covering the entire class of this attack, so the risk persists for now even after it was reported to Microsoft.
Two audiences, two different impacts
What this means
For individuals
Anyone using Copilot for Word with documents obtained from outside sources risks hidden instructions in them affecting the resulting document and spreading to other files they subsequently work with.
For a business
Companies using Copilot for Word on documents from external sources face the risk that hidden malicious instructions will spread unchecked to other internal documents and affect their content without the attacker taking further action.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.