A security researcher has revealed that Microsoft Copilot for Word can be exploited to spread a self-propagating "AI worm" through hidden prompt injections in documents. The attack enables a malicious JSON prompt to be embedded as white text in Word files. When Copilot processes these documents, it reads the hidden instructions and modifies them accordingly, creating a chain reaction that propagates further documents through legitimate user actions.
Currently, there's no full mitigation for this type of attack in large language models like Copilot. Users are advised to treat external documents as untrusted, review them before use, and disable Copilot if necessary to reduce risk.