logo

Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'

ID: 4bda6619-1e88-5351-a893-351c336eef16

STIX ID: report--4bda6619-1e88-5351-a893-351c336eef16

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-06-12

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Aim Security disclosed EchoLeak (CVE-2025-32711), a critical zero-click prompt-injection vulnerability in Microsoft 365 Copilot that could allow attackers to craft emails and use reference-style markdown links to exfiltrate sensitive Copilot context to attacker-controlled domains; Microsoft has patched the issue, assigned a CVSS of 9.3, and reports no known customer impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.