Exploiting Markdown Injection in AI agents: Microsoft Copilot Chat and Google Gemini
ID: 095f9a18-434f-52df-9bbe-3056634244a9
STIX ID: report--095f9a18-434f-52df-9bbe-3056634244a9
Feed Name: Checkmarx Zero
Threat Score
This research report details markdown injection attacks against AI agents (Copilot Chat and Google Gemini) that enable zero-click (image-rendering GET requests) and one-click (malicious links) data exfiltration of sensitive information such as API keys; it demonstrates proof-of-concept exfiltration, analyzes impact and mitigations (Markdown sanitization, CSP), and documents vendor responses (Google: Won't Fix/Infeasible; Microsoft: acknowledged but classified not a vulnerability).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
