Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction

EchoLeak is a new attack method that has been described as a “zero-click” artificial intelligence (AI) vulnerability that enables malicious actors to steal confidential information from the context of Microsoft 365 (M365) Copilot without requiring any user intervention.

The CVE identifier CVE-2025-32711 (CVSS score: 9.3) has been assigned to the critical-rated vulnerability. Microsoft has already resolved it, and no consumer action is necessary. There is no proof that the flaw was intentionally used in the wild.

According to a business advisory issued on Wednesday, an unauthorized attacker can reveal information over a network by using AI command injection in M365 Copilot. Since then, it has been included in Microsoft’s June 2025 Patch Tuesday list, bringing the total number of corrected bugs to 68.

The problem was found and reported by Aim Security, which described it as an example of a large language model (LLM) scope violation read more about Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *