MechanismArticle
An attacker places hidden instructions in a source document that Copilot for Word interprets as part of the user's request, causing it to manipulate the document being edited and copy the instructions into the output, turning that output into a new carrier document.
The attack works by embedding hidden instructions in a source document that Copilot treats as user requests, manipulating the document being drafted and copying the instructions into the resulting output. ✦ AI generated
Article author · Simon Willison's Weblog · 2026-07-29 · original ↗
An attacker places hidden instructions in a document that is later used as source material in Copilot for Word. Copilot may interpret those instructions as part of the user's request, causing it to manipulate the document being drafted or edited. Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier.
Read full article ↗excerpt · fair-use quotation
Around this claim
Context · 2
While hidden white-on-white text is a known technique, this attack is the first to deliberately copy instructions into outputs to achieve self-replication.Article author · Simon Willison's Weblog · conf 85%The vulnerability was responsibly disclosed to Microsoft 144 days ago with no mitigation that covers the full class of attack produced so far.Article author · Simon Willison's Weblog · conf 70%