Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents

gbhackers.com/microsoft…

Security researcher Håkon Måløy disclosed a cross-domain prompt injection vulnerability in Microsoft Copilot for Word that enables a self-propagating “AI worm.” Hidden instructions (for example white-on-white text) inside a document are interpreted by Copilot when the file is used as context. The model can silently alter content such as financial figures and then embed the same malicious prompt into newly generated or edited documents using concealed formatting.

Those downstream documents become new carriers, allowing the attack to spread through normal collaboration workflows without further attacker involvement. The issue was reported to Microsoft in March 2026; after 144 days and multiple mitigations (including model upgrades), the broader attack class remained reproducible as of late July 2026.

Edward Kiledjian @ekiledjian