HeadlinesBriefing favicon HeadlinesBriefing.com

AI Worms Spread Through Copilot for Word

Hacker News •
×

A new vulnerability allows document-borne AI worms to self-propagate through Microsoft Copilot for Word. An attacker can embed hidden instructions in a document, which Copilot may interpret as user commands when processing the document. This can cause Copilot to alter the document being drafted or edited and, crucially, copy the malicious instructions into the new document, turning it into a carrier.

This propagation mechanism extends Cross-Domain Prompt Injection Attacks (XPIAs) from single-interaction compromises to trusted document workflows. If a Copilot-generated or edited document containing these hidden instructions is later used as source material in another Copilot-assisted workflow, the attack can re-trigger and spread further, even without the original malicious document. This represents one of the first public demonstrations of such document-borne AI-worm self-propagation within a mainstream productivity suite.

Microsoft has been aware of the issue and engaged in a coordinated disclosure process. While initial mitigation attempts were made, including a model upgrade to GPT-5.6, the vulnerability class reportedly remains exploitable at the time of disclosure. Customers are advised to treat externally sourced documents as untrusted when used with Copilot, review documents before use, and carefully check Copilot-generated content.