Word Copilot can spread hidden document instructions
Microsoft Copilot for Word can follow hidden instructions inside documents and alter business content. It can also copy those instructions into new documents, allowing the problem to spread through normal sharing.
- Report priority
- Medium
- Targets
- Microsoft Copilot for Word
How it works
- An attacker hides instructions inside a document shared with the organization.
- When Copilot uses that document as source material, it may treat the hidden text as part of the user's request.
- Copilot can then alter the document being drafted or edited and copy the hidden instructions into the result.
- If that document is reused with Copilot, the instructions can trigger again and spread further.
What to do
Check whether your organization uses Copilot for Word and whether employees use shared or attached documents as Copilot source material. Review Copilot-generated or Copilot-edited documents for unexpected changes before treating them as trusted.
Treat externally sourced documents as untrusted when using Copilot. Review attachments before starting Copilot work, then carefully check every Copilot-generated or Copilot-edited document before sharing or reusing it.
Technical details
This is a cross-domain prompt-injection issue in Copilot for Word. Hidden document text can reach the underlying language model as readable instructions, allowing Copilot to alter content and copy those instructions into downstream documents. Testing reproduced the behavior across multiple Copilot configurations and models, including GPT-5.5 and GPT-5.6.
References
- enklypesalt.com · context-collapse-part3-ai-worming-through-word Cyber Security News
- any.run · enterprise Cyber Security News
- thehackernews.com · teleshim-abuses-telegram-for-c2-in.html TheHackerNews
- infosecurity-magazine.com · ai-linux-kernel-zero-day-net-sched Infosecurity Magazine