← Back to Feed
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
July 30, 2026 · The Hacker News · Severity: MEDIUM
Microsoft Copilot for Word can propagate hidden prompts from source documents into new files it generates. Researcher Håkon Måløy disclosed the technique on July 28 after reporting it to Microsoft 144 days earlier. Microsoft deployed two mitigations (blocking the original prompt wording and upgrading to GPT-5.5), but Måløy demonstrated the attack still works with modified instructions on GPT-5.6 the next day, and the vulnerability class remained exploitable at publication. The attack is not zero-click and requires a Copilot drafting operation with a malicious document in context.
Key Takeaways
- Hidden instructions in Word documents can propagate through Microsoft 365 Copilot into newly generated files, enabling manipulation of report figures and continued instruction injection.
- Microsoft's mitigations (prompt blocking and model upgrade to GPT-5.5) were bypassed within a day using modified instructions on GPT-5.6, indicating the vulnerability class remains uncontained.
- The attack requires user interaction (a Copilot drafting operation) and a malicious document as an attachment or OneDrive source, so it is not a zero-click exploit.