logo
AI Security Alarm: Microsoft Copilot Vulnerability Exposed Sensitive Data via Zero-Click Email Exploit

AI Security Alarm: Microsoft Copilot Vulnerability Exposed Sensitive Data via Zero-Click Email Exploit

Hans India12-06-2025
In a major first for the AI security landscape, researchers have identified a critical vulnerability in Microsoft 365 Copilot that could have allowed hackers to steal sensitive user data—without the user ever clicking a link or opening an attachment. Known as EchoLeak, this zero-click flaw revealed how deeply embedded AI assistants can be exploited through subtle prompts hidden in regular-looking emails.
The vulnerability was discovered by Aim Labs in January 2025 and promptly reported to Microsoft. It was fixed server-side in May, meaning users didn't need to take any action themselves. Microsoft emphasized that no customers were affected, and there's no evidence that the flaw was exploited in real-world scenarios.
Still, the discovery marks a historic moment, as EchoLeak is believed to be the first-ever zero-click vulnerability targeting a large language model (LLM)-based assistant.
How EchoLeak Worked
Microsoft 365 Copilot integrates across Office applications like Word, Excel, Outlook, and Teams. It utilizes AI, powered by OpenAI's models and Microsoft Graph, to help users by analyzing data and generating content based on internal emails, documents, and chats.
EchoLeak took advantage of this feature. Here's a breakdown of the exploit process:
A malicious email is crafted to look legitimate but contains a hidden prompt embedded in the message.
When a user later asks Copilot a related question, the AI, using Retrieval-Augmented Generation (RAG), pulls in the malicious email thinking it's relevant.
The concealed prompt is then activated, instructing Copilot to leak internal data through a link or image.
As the email is displayed, the link is automatically accessed by the browser, silently transferring internal data to the attacker's server.
Researchers noted that certain markdown image formats used in the email could trigger browsers to send automatic requests, enabling the leak. While Microsoft's Content Security Policies (CSP) block most unknown web requests, services like Teams and SharePoint are considered trusted by default—offering a way in for attackers.
The Bigger Concern: LLM Scope Violations
The vulnerability isn't just a technical bug—it signals the emergence of a new category of threats called LLM Scope Violations. These occur when language models unintentionally expose data through their internal processing mechanisms, even without direct user commands.
'This attack chain showcases a new exploitation technique... by leveraging internal model mechanics,' Aim Labs stated in their report. They also cautioned that similar risks could be present in other RAG-based AI systems, not just Microsoft Copilot.
Microsoft assigned the flaw the ID CVE-2025-32711 and categorized it as critical. The company reassured users that the issue has been resolved and that there were no known incidents involving the vulnerability.
Despite the fix, the warning from researchers is clear: "The increasing complexity and deeper integration of LLM applications into business workflows are already overwhelming traditional defences,' their report concludes.
As AI agents become more integrated into enterprise systems, EchoLeak is a stark reminder that security in the age of intelligent software needs to evolve just as fast as the technology itself.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Nvidia set to become the world's most valuable company in history
Nvidia set to become the world's most valuable company in history

Business Standard

timean hour ago

  • Business Standard

Nvidia set to become the world's most valuable company in history

Nvidia was on track to become the most valuable company in history on Thursday, with the chipmaker's market capitalization reaching $3.92 trillion as Wall Street doubled down on optimism about AI. Shares of the leading designer of high-end AI chips were up 2.2 per cent at $160.6 in morning trading, giving the company a higher market capitalization than Apple's record closing value of $3.915 trillion on December 26, 2024. Nvidia's newest chips have made gains in training the largest artificial-intelligence models, fueling demand for products by the Santa Clara, California, tech company. Microsoft is currently the second-most valuable company on Wall Street, with a market capitalization of $3.7 trillion as its shares rose 1.4 per cent on $498. Apple rose 0.5 per cent, giving it a stock market value of $3.19 trillion, in third place. A race among Microsoft, Meta Platforms , Alphabet and Tesla to build AI datacenters and dominate the emerging technology has fueled insatiable demand for Nvidia's high-end processors. The stock market value of Nvidia, whose core technology was developed to power video games, has nearly octupled over the past four years from $500 billion in 2021. Nvidia is now worth more than the combined value of the Canadian and Mexican stock markets, according to LSEG data. The tech company also exceeds the total value of all publicly listed companies in the United Kingdom. Nvidia recently traded at about 32 times analysts' expected earnings for the next 12 months, below its average of about 41 over the past five years, according to LSEG data. That relatively modest price-to-earnings valuation reflects steadily increasing earnings estimates that have outpaced Nvidia's sizable stock gains. The company's stock has now rebounded more than 68 per cent from its recent closing low on April 4, when Wall Street was reeling from President Donald Trump's global tariff announcements. U.S. stocks, including Nvidia, have recovered on expectations that the White House will cement trade deals to soften Trump's tariffs.

Nvidia set to become the world's most valuable company in history
Nvidia set to become the world's most valuable company in history

Economic Times

timean hour ago

  • Economic Times

Nvidia set to become the world's most valuable company in history

Nvidia was on track to become the most valuable company in history on Thursday, with the chipmaker's market capitalization reaching $3.92 trillion as Wall Street doubled down on optimism about AI. Shares of the leading designer of high-end AI chips were up 2.2% at $160.6 in morning trading, giving the company a higher market capitalization than Apple's record closing value of $3.915 trillion on December 26, 2024. Nvidia's newest chips have made gains in training the largest artificial-intelligence models, fueling demand for products by the Santa Clara, California, tech company. Microsoft is currently the second-most valuable company on Wall Street, with a market capitalization of $3.7 trillion as its shares rose 1.4% on $498. Apple rose 0.5%, giving it a stock market value of $3.19 trillion, in third place. A race among Microsoft, Meta Platforms , Alphabet and Tesla to build AI data centers and dominate the emerging technology has fueled insatiable demand for Nvidia's high-end processors. The stock market value of Nvidia, whose core technology was developed to power video games, has nearly octupled over the past four years from $500 billion in 2021. Nvidia is now worth more than the combined value of the Canadian and Mexican stock markets, according to LSEG data. The tech company also exceeds the total value of all publicly listed companies in the United Kingdom. Nvidia recently traded at about 32 times analysts' expected earnings for the next 12 months, below its average of about 41 over the past five years, according to LSEG data. That relatively modest price-to-earnings valuation reflects steadily increasing earnings estimates that have outpaced Nvidia's sizable stock gains. The company's stock has now rebounded more than 68% from its recent closing low on April 4, when Wall Street was reeling from President Donald Trump's global tariff announcements. U.S. stocks, including Nvidia, have recovered on expectations that the White House will cement trade deals to soften Trump's tariffs.

Microsoft to cut about 4% of jobs amid hefty AI bets
Microsoft to cut about 4% of jobs amid hefty AI bets

Time of India

timean hour ago

  • Time of India

Microsoft to cut about 4% of jobs amid hefty AI bets

Microsoft will lay off nearly 4% of its workforce, the company said on Wednesday, in the latest job cuts as the tech giant looks to rein in costs amid hefty investments in artificial intelligence infrastructure. The company, which had about 228,000 employees worldwide as of June 2024, had announced layoffs in May, affecting around 6,000 workers. It was planning to cut thousands of jobs, particularly in sales, Bloomberg News reported last month. The Windows maker had pledged $80 billion in capital spending for its fiscal year 2025. However, the soaring cost of scaling its AI infrastructure has weighed on its margins, with its June quarter cloud margin expected to shrink from last year. Microsoft said on Wednesday it planned to reduce organizational layers with fewer managers and streamline its products, procedures and roles. The Seattle Times first reported on the layoffs earlier on Wednesday. Separately, Bloomberg News reported Microsoft's Barcelona-based King division, which makes the Candy Crush video game, is cutting 10% of its staff, or about 200 jobs. Big Tech peers, which are investing heavily in artificial intelligence, have also announced job cuts. Facebook parent Meta earlier this year said it would trim about 5% of its "lowest performers", while Alphabet's Google has also laid off hundreds of employees in the past year. Amazon has also cut jobs across its business segments, most recently in its books division. The company had earlier laid off employees in its devices and services unit, and communications staff. Economic uncertainties and rising costs have triggered layoffs across sectors in Corporate America, as companies rush to streamline operations and hedge against further cost pressures.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store