Word worm crawls into Copilot, spreads chaos
A researcher has disclosed a vulnerability in Microsoft Copilot for Word that could let hidden instructions in an untrusted document influence Copilot’s output and copy themselves into newly generated files. This matters because the technique could spread through ordinary document-sharing workflows, quietly altering content such as financial figures and making the original source difficult to trace.
Norwegian AI researcher Håkon Måløy said he had coordinated with Microsoft since March 2026, but that two mitigation attempts, including a model upgrade, had not robustly addressed the wider problem. In his example, malicious text concealed in a downloaded Word document instructs Copilot to change a report and embed the same instructions in it; a later user who uses that report as source material could then continue the cycle without an attacker accessing the organisation’s Microsoft 365 tenant.
- Hidden Word content could manipulate Copilot-generated documents.
- The malicious instructions may propagate through shared files.
- Microsoft’s mitigations reportedly have not closed the wider vulnerability.