Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot

Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot

EchoLeak is the first known zero-click AI vulnerability that allows attackers to exfiltrate sensitive data from Microsoft 365 Copilot without user interaction. Although patched by Microsoft, the vulnerability highlights the risks of โ€˜LLM Scope Violationโ€™ in AI-integrated enterprise systems. #EchoLeak #Microsoft 365Copilot #LLMScopeViolation

Keypoints

  • EchoLeak is a zero-click vulnerability that exploits Microsoft 365 Copilotโ€™s AI capabilities.
  • The attack involves a malicious email with a crafted prompt designed to exfiltrate internal data.
  • The vulnerability was assigned CVE-2025-32711 and fixed by Microsoft in May 2025.
  • It demonstrates the threat of โ€˜LLM Scope Violation,โ€™ where large language models leak privileged information.
  • enterprises should improve prompt filtering, input scoping, and RAG engine configurations to prevent similar attacks.

Read More: https://www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/