Researcher says Microsoft Copilot for Word can spread hidden malicious instructions from one document into new files

A researcher says a booby-trapped Word document can make Microsoft Copilot for Word change what it writes and silently copy the hidden instructions into newly created documents. The issue was disclosed after about 144 days of coordination with Microsoft, which reportedly mitigated the original proof of concept but not the broader vulnerability class. The attack uses hidden text embedded in a source document that Copilot treats as instructions instead of untrusted content, creating a document-borne prompt-injection worm that can persist without the attacker having access to the victim's Microsoft 365 tenant.
Why it matters: Organizations using Copilot for Word could have reports or other business documents silently altered and contaminated just by including an untrusted document in Copilot's context. There is no robust fix described yet, so users should be cautious with externally sourced Word files and limit what documents Copilot can ingest.

Sources

Word worm crawls into Copilot, spreads chaos
2026.07.29 100% relevant
This article appears to be the first tracked disclosure of this specific Copilot for Word document-borne self-propagating prompt-injection issue, and it does not clearly match an existing tracked story about the same underlying event.
← Back to all stories