Aim Labs disclosed a zero-click chain in which an email containing hidden instructions, once retrieved by Microsoft 365 Copilot, could cause Copilot to embed internal data in an auto-loaded image request to an attacker. Microsoft rated CVE-2025-32711 critical, fixed it server-side in May 2025, and stated there was no evidence of real-world exploitation.
Why it matters
Its discoverers describe it as the first real-world zero-click prompt injection exploit with data exfiltration in a production LLM system.
Key facts
As stated in the sources, with where to find them.
- Aim Labs devised the attack in January 2025; Microsoft deployed a server-side fix in May 2025.BleepingComputer article body
- The arXiv case study lists bypassed defenses including Microsoft's cross-prompt-injection classifier and link redaction.arXiv abstract
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Aug 6, 2025
Jun 11, 2025
Jul 8, 2025
Jun 16, 2025
May 26, 2025
May 22, 2025