A security researcher revealed a method to exploit Microsoft Copilot for Word by embedding a self-propagating AI worm through hidden text in documents. This AI worm can spread without the use of macros, leveraging normal document-sharing processes. The attack takes advantage of prompt injection vulnerabilities in the Copilot system, which allows malicious prompts to be integrated into user-generated documents quietly.
Multiple mitigations from Microsoft have been unable to completely prevent this type of attack due to inherent weaknesses in the architecture of current large language models (LLMs). To enhance safety, users are advised to treat external documents as untrusted, verify documents before use, and consider disabling Copilot in Word.