Chronicle/Attacks & incidents

EchoLeak: zero-click prompt injection in Microsoft 365 Copilot (CVE-2025-32711)

AttackVulnerability disclosureSignificance assistant-drafted

Aim Labs disclosed a zero-click chain in which an email containing hidden instructions, once retrieved by Microsoft 365 Copilot, could cause Copilot to embed internal data in an auto-loaded image request to an attacker. Microsoft rated CVE-2025-32711 critical, fixed it server-side in May 2025, and stated there was no evidence of real-world exploitation.

Why it matters

Its discoverers describe it as the first real-world zero-click prompt injection exploit with data exfiltration in a production LLM system.

Key facts

As stated in the sources, with where to find them.

  • Aim Labs devised the attack in January 2025; Microsoft deployed a server-side fix in May 2025.BleepingComputer article body
  • The arXiv case study lists bypassed defenses including Microsoft's cross-prompt-injection classifier and link redaction.arXiv abstract

Findings that cite this record

Key questions this bears on

Sources

Related records