
Persistent Data Exfiltration Attack on Microsoft Copilot via Prompt Injection and CSP Bypass
Cybersecurity researcher Johan demonstrates a persistent data exfiltration attack against Microsoft Copilot (M365 enterprise version) using prompt injection, CSP bypass, and memory poisoning. The exploit chain involves embedding malicious instructions in a Word, Excel, or SharePoint document that, when summarized via Copilot, triggers a font-based CSP bypass to exfiltrate sensitive data (e.g., passwords) via a remote font URL. The attack persists in Copilot’s memory, activating whenever a user mentions keywords like 'password' or 'code' in future conversations. Johan also highlights a delayed tool invocation technique to improve exploit reliability and notes the vulnerability affected multiple Microsoft products, including Outlook and PowerPoint. The exploit was discovered using Copilot itself to identify CSP bypasses, and Microsoft assigned a CVE for the issue. The attack requires no user clicks, macros, or file downloads—only interaction with Copilot’s built-in features.