Microsoft Copilot Cowork Exfiltrates Files
Microsoft Copilot Cowork vulnerability enables file exfiltration via prompt injection and rendered images
“Because these messages can contain external images that trigger network requests to external websites, data can be exfiltrated when a user opens a compromised message sent by the agent.”
A security vulnerability in Microsoft Copilot Cowork allowed prompt injection attacks to exfiltrate files by having agents send emails containing external images that leak data via network requests. OneDrive pre-authenticated download links could be embedded and leaked, giving attackers access to user files. This highlights the persistent challenge of securing agentic AI systems against data exfiltration — a critical concern as enterprise AI agents gain broader file and email access.