{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/echoleak-m365-copilot-cve-2025-32711-2025/",
 "asOf": "2026-09-26",
 "id": "echoleak-m365-copilot-cve-2025-32711-2025",
 "date": "2025-06-11",
 "datePrecision": "day",
 "title": "EchoLeak: zero-click prompt injection in Microsoft 365 Copilot (CVE-2025-32711)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Aim Labs disclosed a zero-click chain in which an email containing hidden instructions, once retrieved by Microsoft 365 Copilot, could cause Copilot to embed internal data in an auto-loaded image request to an attacker. Microsoft rated CVE-2025-32711 critical, fixed it server-side in May 2025, and stated there was no evidence of real-world exploitation.",
 "whyItMatters": "Its discoverers describe it as the first real-world zero-click prompt injection exploit with data exfiltration in a production LLM system.",
 "actors": [
  "aim-security",
  "microsoft"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://arxiv.org/abs/2509.10540",
   "publisher": "arXiv",
   "title": "EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System",
   "date": "2025-09-06",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/",
   "publisher": "BleepingComputer",
   "title": "Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot",
   "date": "2025-06-11",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Aim Labs devised the attack in January 2025; Microsoft deployed a server-side fix in May 2025.",
   "locator": "BleepingComputer article body"
  },
  {
   "fact": "The arXiv case study lists bypassed defenses including Microsoft's cross-prompt-injection classifier and link redaction.",
   "locator": "arXiv abstract"
  }
 ],
 "significance": 5,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "indirect-prompt-injection",
  "injection-classifiers"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}