logo

Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft

ID: 8f21aec7-1cfa-5329-9a42-0fefe0e332ef

STIX ID: report--8f21aec7-1cfa-5329-9a42-0fefe0e332ef

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-06-13

Date Updated: 2026-04-22

...
...

Aim Labs disclosed 'EchoLeak', a zero-click RAG/LLM vulnerability in Microsoft 365 Copilot that uses an 'LLM Scope Violation' indirect prompt-injection technique to automatically exfiltrate sensitive data from Copilot's context (mailbox, OneDrive, SharePoint, Teams, Office files). The report outlines an attack chain including XPIA bypass, link/image redaction bypass and CSP bypass, warns the technique can generalize to other RAG apps, and states Microsoft was informed in January 2025 and patched the issue in May 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.