TechDogs-"Microsoft Copilot For Word Can Copy Hidden Prompts Despite 2 Mitigations"

Cyber Security

Microsoft Copilot For Word Can Copy Hidden Prompts Despite 2 Mitigations

By Utkarsh Hiwale

Updated on Thu, Jul 30, 2026

Overall Rating


Microsoft Copilot for Word can be manipulated by hidden instructions inside a document, causing the AI assistant to alter business content and copy the concealed prompt into new files that may affect later Copilot-assisted workflows.


The technique, disclosed by security researcher Håkon Måløy after coordinated work with Microsoft, behaves like a document-borne AI worm. However, it does not spread automatically and requires a user to invoke Copilot with an affected file in its context.


TL;DR

 
  • Hidden white-on-white instructions can be read by Copilot even when users cannot see them.
  • In a proof of concept, Copilot halved financial figures and copied the hidden prompt into a new document.
  • Microsoft deployed two mitigations, but the researcher said the broader attack class remained exploitable on July 28, 2026.


How Can Hidden Prompts Spread Through Microsoft Word?


Måløy reported the issue to the Microsoft Security Response Center on March 6, 2026, and publicly disclosed it on July 28 after a 144-day coordination period. Microsoft confirmed the behavior on March 31 and deployed two mitigations, including an upgrade of the underlying model to GPT-5.5 on July 14, according to the researcher’s disclosure.


However, Måløy said he reproduced the full attack chain with a modified prompt using GPT-5.6 on July 15 and again on July 28.


“The vulnerability class therefore remains exploitable at the time of publication,” he wrote.


The attack starts when malicious instructions are placed inside an otherwise normal Word document. They can be concealed using white text on a white background and a small font, making them invisible to the person reviewing the file.


According to Måløy, Copilot for Word strips formatting such as font color and size before passing document text to the large language model. As a result, the concealed text remains readable to Copilot, which may mistake the attacker’s instructions for part of the user’s request.

TechDogs ImageSource


In the proof of concept, a malicious market analysis was used as source material for a financial report. Copilot silently halved every financial figure, copied the prompt into the generated report using white eight-point text, and did not disclose either action.


That generated report then became a new carrier. When it was attached to a later drafting session without the original malicious file, the prompt triggered again, altered a second report, and copied itself forward.


The Hacker News noted that this is not a zero-click attack or conventional malware. Each stage requires another Copilot drafting or editing operation, and the affected document must be attached, selected as a source, or judged relevant by Work IQ from content the user can already access.


What Has Microsoft Said About Prompt Injection?


The Hacker News reported that it found no public CVE or standalone Microsoft advisory for this specific Word finding as of July 30, 2026. It also noted that no exploitation in the wild had been reported.


Microsoft’s support documentation says Copilot for Word can ground a new draft on up to 20 files, emails, or meetings. Edit with Copilot can also use Work IQ to locate relevant organizational content.


Microsoft advises users to verify and modify Copilot-generated drafts before accepting them. For shared documents, the company says users must review and confirm suggested Edit with Copilot changes before they are applied.


In separate security guidance, Microsoft describes hidden text in documents and attachments as a known prompt-injection vector. The company says Microsoft 365 Copilot uses runtime safeguards, while Defender for Office 365 can inspect inbound email for prompt injection as another defensive layer.


Microsoft has also acknowledged the architectural challenge behind persistent AI context.


“Prompting alone is not a reliable security boundary,” the company said in a June 2026 security post, adding that provenance, access controls, and isolation should be enforced outside the model.


What Should Microsoft 365 Copilot Users Do?


Måløy said no customer-side remediation fully addresses the broader issue. He recommended treating externally sourced documents as untrusted, reviewing files before using them as Copilot source material, and checking AI-generated or edited documents before sharing or reusing them.

 



Organizations should also consider restricting which documents Copilot can process, applying sensitivity labels, using data-loss-prevention controls, and investigating unexplained changes in AI-generated business documents. Microsoft’s Purview documentation says administrators can prevent Copilot from processing files with selected sensitivity labels, although such controls do not represent a complete fix for the attack class.


The finding highlights a wider enterprise AI security problem. Once malicious instructions are copied into trusted internal documents, the original source can disappear from the workflow, making manipulation harder to trace and allowing compromised information to influence later decisions.

First published on Thu, Jul 30, 2026

Enjoyed what you've read so far? Great news - there's more to explore!

Stay up to date with the latest news, a vast collection of tech articles including introductory guides, product reviews, trends and more, thought-provoking interviews, hottest AI blogs and entertaining tech memes.

Plus, get access to branded insights such as informative white papers, intriguing case studies, in-depth reports, enlightening videos and exciting events and webinars from industry-leading global brands.

Dive into TechDogs' treasure trove today and Know Your World of technology!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light