CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3514

As cited

Copy frozen at (site build).

ai security

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

A researcher disclosed a technique where hidden instructions embedded in Word documents can cause Microsoft 365 Copilot to rewrite content and propagate those same hidden instructions into newly generated files. The vulnerability was reported to Microsoft on July 28 after a 144-day disclosure period, and proof of concept testing showed the malicious instructions persisted across multiple Copilot sessions.

Why it matters: Organizations using Microsoft 365 Copilot for Word face supply chain and data integrity risks, as documents could be weaponized to inject hidden instructions that persist through AI-assisted edits and potentially reach downstream users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Microsoft 365 Copilot in Word can be manipulated by hidden instructions embedded in documents to alter content, and these instructions can propagate to newly generated files. Håkon Måløy demonstrated the issue on July 28, 2026, after a 144-day disclosure period with Microsoft.

Why it matters: Organizations using Microsoft 365 Copilot for document generation face the risk that adversaries could inject hidden prompts into source documents to compromise the integrity of outputs, and the propagation of these prompts into new files multiplies the exposure across workflows.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Microsoft 365 Copilot in Word can be manipulated by hidden instructions embedded in documents to alter content, and these instructions can propagate to newly generated files. Håkon Måløy demonstrated the issue on July 28, 2026, after a 144-day disclosure period with Microsoft.

Why it matters: Organizations using Microsoft 365 Copilot for document generation face the risk that adversaries could inject hidden prompts into source documents to compromise the integrity of outputs, and the propagation of these prompts into new files multiplies the exposure across workflows.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary