Microsoft Copilot Cowork Exfiltrates Files

Simon Willison's Blog News

Summary

A security vulnerability in Microsoft Copilot Cowork allows attackers to exfiltrate files by exploiting prompt injection that triggers external image requests, potentially leaking pre-authenticated download links.

No content available
Original Article
View Cached Full Text

Cached at: 05/26/26, 06:46 PM

# Microsoft Copilot Cowork Exfiltrates Files Source: [https://simonwillison.net/2026/May/26/copilot-cowork-exfiltrates-files/](https://simonwillison.net/2026/May/26/copilot-cowork-exfiltrates-files/) 26th May 2026 \- Link Blog **[Microsoft Copilot Cowork Exfiltrates Files](https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files)**\([via](https://news.ycombinator.com/item?id=48272354)\) The biggest challenge in designing agentic systems continues to be preventing them from enabling attackers to exfiltrate data\. In this case Microsoft Copilot Cowork \(yes, that's[a real product name](https://www.microsoft.com/en-us/microsoft-365/blog/2026/03/09/copilot-cowork-a-new-way-of-getting-work-done/)\) was allowing agents to send emails to the user's own inbox without approval\.\.\. but those messages were then displayed in a way that could leak data to an attacker via rendered images: > Because these messages can contain external images that trigger network requests to external websites, data can be exfiltrated when a user opens a compromised message sent by the agent\. Since OneDrive can create pre\-authenticated download links, a successful prompt injection could cause those links to be leaked, allowing files to be downloaded by the attacker\.

Similar Articles

Microsoft Copilot Cowork Exfiltrates Files

Hacker News Top

Researchers at PromptArmor demonstrate that Microsoft Copilot Cowork can be exploited via indirect prompt injection to exfiltrate files from Microsoft 365, exploiting the lack of approval for certain actions when the recipient is the active user.

Critical Copilot vulnerability allowed hackers to seal 2FA code from users

Ars Technica

A critical vulnerability in Microsoft 365 Copilot, dubbed SearchLeak, allowed attackers to steal 2FA codes via parameter-to-prompt injection by exploiting raw HTML rendering before guardrail enforcement. Microsoft has fixed the vulnerability, but the underlying issue of prompt injection remains a challenge.

Document-borne AI worms can self-propagate through Copilot for Word

Hacker News Top

This article demonstrates a novel AI worm that can self-propagate through Microsoft's Copilot for Word by embedding hidden instructions in documents, causing Copilot to copy those instructions into new documents. The vulnerability was disclosed to Microsoft's Security Response Center.