A security researcher has discovered a vulnerability in Microsoft's Copilot for Word that allows malicious instructions to be hidden within documents using invisible formatting. These hidden instructions can manipulate financial figures and, critically, propagate themselves into newly generated documents, effectively turning user workflows into a distribution mechanism. Existing security tools, designed to detect macros or malicious code, are ill-equipped to identify this form of prompt injection, which exploits the model's inability to distinguish between user-intended content and hidden instructions. AI
IMPACT Highlights a new class of prompt injection attacks targeting document-based AI assistants, potentially impacting data integrity and security in enterprise workflows.
RANK_REASON Disclosure of a vulnerability in a specific AI-powered product feature.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →