EchoLeak (CVE-2025-32711)
A June 2025 zero-click indirect prompt injection vulnerability in Microsoft 365 Copilot disclosed by Aim Security, scored CVSS 9.3. An attacker could send an email containing hidden instructions; when a user asked Copilot to summarize their inbox, the assistant consumed the email, followed the hidden instructions, and exfiltrated sensitive tenant data—without the user clicking anything. EchoLeak was the first widely-covered 'zero-click' LLM attack and became the canonical example of why indirect prompt injection is treated as a top-tier enterprise risk in 2026 threat models.
Frequently asked questions
- Was EchoLeak patched?
- Yes, Microsoft shipped mitigations shortly after disclosure. But the underlying attack class—Indirect Prompt Injection (XPIA)—is architectural, not a single bug. Similar variants continue to be found across other AI-integrated productivity tools; the patch closed one specific path, not the vulnerability class.