Expert warns this dangerous Microsoft Word worm can burrow into Copilot and cause havoc — here's what we know | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
Expert warns this dangerous Microsoft Word worm can burrow into Copilot and cause havoc — here's what we know
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Instructions hidden as white text in a Word document can make Microsoft 365 Copilot silently alter the file it is drafting and copy the instructions into the output
Each poisoned document becomes a carrier, so the attack spreads through ordinary internal workflows without the original malicious file and needs no macros, malware, or code execution
Microsoft has shipped two mitigations across a 144-day disclosure, including a model upgrade, and the attack was still reproducible by the researcher
A security researcher has published a proof of concept showing that instructions hidden inside a Word document can cause Microsoft 365 Copilot to silently alter the file it is drafting, then copy those same instructions into the finished document, so the next person to use it becomes a carrier too.
Håkon Måløy, a data scientist with a doctorate in applied machine learning, disclosed the technique as the third installment of his Context Collapse series, after a 144-day coordinated disclosure with the Microsoft Security Response Center.
The reason this is being reported ahead of a fix is that it still works despite multiple attempts by Microsoft, as he notes that no robust mitigation for the broader vulnerability class is currently available.
A clever attack designed around Copilot's approach to text
The underlying attack belongs to a family known as cross-domain prompt injection, or XPIA. An attacker writes instructions in a natural-language document, formats them as white text on a white background at a small point size, and shares the file.
Because Copilot for Word strips formatting before passing text to the underlying language model, the model reads text the human never sees. This is true even for documents that are not opened by the user on purpose: The attack can trigger either when a user manually attaches a document to Copilot or when Copilot, working in Work IQ mode, searches the user's One Drive for relevant files and finds the malicious one on its own.
Microsoft 365 Copilot could be turned into a one-click data theft tool
Microsoft warns AI agents are being 'Auto Jack'-ed by browsing untrusted websites
Top AI tools such as Open Claw and Github Copilot can be hijacked to create new massive botnets
It is also more dangerous than other exploits because of one key element: propagation. The hidden prompt in Måløy's proof of concept had two parts. One instructed Copilot to alter the document being drafted, in his demonstration halving every financial figure in a quarterly report.
The other instructed Copilot to copy the prompt into the new document and conceal it, framed innocuously as source tracking and readability formatting. Copilot did both, appending the instructions in white text and mentioning neither action to the user.
The disclosure timeline is the most uncomfortable part of the report. Måløy reported to MSRC on March 6 2026. Microsoft confirmed the behavior on March 31 and shipped a first mitigation in early April via a reworked Edit with Copilot experience, which successfully blocked his original prompt wording. He reproduced the attack with different wording the same week, and a second case was opened.
The second fix, on July 14, consisted of upgrading the underlying model to GPT-5.5. Måløy broke it the following day using GPT-5.6, then voluntarily offered Microsoft a further two-week delay to attempt another mitigation. The class still reproduced on the disclosure date, indicating that although a fix is in the works, the exploit is still possible to run.
A complicated issue that lacks a proper resolution
The issue goes far beyond Microsoft Word: an AI assistant must ingest untrusted content to determine whether it is relevant or hostile. But the content enters the same context window as the system prompt and the user's actual request, so by the time the model evaluates whether the text is an attack, the attacker's tokens have already shaped that evaluation.
The enemy within: how to stop a simple Teams message taking down your business
Security experts warn Claude Code can be exploited simply by trying to be helpful
Experts warn Chat GPT's Workspace Agent Builder can be hijacked to create malicious AI workers
As Måløy puts it, "the content being inspected participates in the act of inspection."
Microsoft confirmed it had reviewed the findings in a statement to The Register but stopped short of indicating a timeline for a complete fix:
“We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure," the company said.
"To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.”
Måløy's recommendations are to treat externally sourced documents as untrusted when using them with Copilot, review attachments before starting an AI-assisted draft, and review Copilot's output carefully before sharing or reusing it.
He also suggested that generated documents should carry provenance metadata that records source material and model edits, which would not prevent injection but would make an infection traceable after the fact.
With Copilot extending further into agentic products that create and manipulate documents with less human oversight, the scope of how exploits like this could affect workflows (and users) will widen rather than narrow, and a complete solution is not yet in sight.
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.
You must confirm your public display name before commenting
What kind of i Phone gamer are you? Find out in our quiz and get some hand-picked Apple Arcade recommendations
I played all 279 Apple Arcade games — here are the eight best, from genius quick puzzlers to addictive life sims
Blank spaces could hold danger - Kaspersky report warns of the dangers of 'parked domains' and empty pages where hackers could be lurking
After three weeks wearing the Meta Ray-Ban Scriber Optics I couldn't be more in love — I just wish smart glasses weren’t so controversial
Apple Arcade is a joyful reminder of when mobile gaming was about fun, not emptying your wallet
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



