FactArticle
The vulnerability was responsibly disclosed to Microsoft 144 days ago with no mitigation that covers the full class of attack produced so far.
Håkon Måløy responsibly disclosed the vulnerability to Microsoft, who had 144 days to develop a fix, but no comprehensive mitigation for this class of attack exists yet. ✦ AI generated
Article author · Simon Willison's Weblog · 2026-07-29 · original ↗
It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far (unsurprisingly) there's no mitigation that covers the full class of attack.
Read full article ↗excerpt · fair-use quotation
Around this claim
In practice · 1
This moment responds to
provides context → Håkon Måløy discovered a prompt injection variant against Microsoft Word that achieves full self-replicating worm behavior.Article author · Simon Willison's Weblogprovides context → An attacker places hidden instructions in a source document that Copilot for Word interprets as part of the user's request, causing it to manipulate the document being edited and copy the instructions into the output, turning that output into a new carrier document.Article author · Simon Willison's Weblogprovides context → A carrier document, when used in subsequent Copilot-assisted workflows, triggers the hidden instructions again and propagates them into further documents even without the attacker's original document being present.Article author · Simon Willison's Weblog