logo

Echoleak- Send a prompt , extract secret from Copilot AI!( CVE-2025-32711)

ID: e18fcfff-f96d-5c63-8d64-d5c02b84e620

STIX ID: report--e18fcfff-f96d-5c63-8d64-d5c02b84e620

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-09-12

Date Updated: 2026-04-30

Author: Nandini Seth

...
...

EchoLeak is a documented zero-click prompt-injection vulnerability in Microsoft 365 Copilot where a crafted email or document causes Copilot to process hidden instructions, extract sensitive internal context (emails, chats, documents, tokens), and embed that data into attacker-controlled markdown links that trigger exfiltration. The report outlines the attack chain, demonstrates how automatic rendering and lack of prompt isolation enable the leak, and recommends mitigations including prompt isolation, input sanitization, disabling auto-rendering of untrusted content, restricting AI context access, monitoring AI output, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.