Copilot for Word AI Worm: Hidden White-on-White Instructions Spread Self-Propagating XPIA Through Enterprise Document Workflows — 144 Days After Disclosure, Architectural Problem Unresolved
Security researcher Håkon Måløy disclosed a self-propagating AI worm in Microsoft Copilot for Word — 144 days after initial MSRC report. Hidden white-on-white text in Word documents is invisible to users but fully legible to Copilot after formatting strip. Copilot alters content silently and copies the payload into output documents. The infected output spreads the worm to the next Copilot session without the original file. Microsoft deployed mitigations blocking specific PoC payloads — but the architectural problem is unresolved: LLMs cannot reliably distinguish untrusted document content from authoritative instructions. Modified payloads confirmed working through July 28.
