mimile
Back to feed

Aim Labs researchers find first zero-click AI flaw in M365 Copilot, patched in May 2025

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Aim Labs researchers find first zero-click AI flaw in M365 Copilot, patched in May 2025

Aim Labs researchers have discovered a zero-click vulnerability in Microsoft 365 Copilot that enables exfiltration of sensitive corporate data with a single email. Microsoft patched the flaw, dubbed EchoLeak, in May 2025 after being notified in January. The finding is the first zero-click AI vulnerability ever discovered.

The EchoLeak Flaw

Aim Labs researchers identified EchoLeak, a zero-click vulnerability in Microsoft 365 Copilot that exploits design flaws in Retrieval Augmented Generation (RAG) systems. The flaw allows attackers to automatically exfiltrate sensitive data from Copilot's context, including files from Word, Excel, Outlook, and Teams, without any user interaction. Copilot's permission model ensures users only access their own files, but those files may contain proprietary or compliance-sensitive information. The vulnerability is the first zero-click AI flaw ever discovered, according to the researchers' June 11 report.

LLM Scope Violation

The researchers used a new exploitation technique called LLM Scope Violation, a form of indirect prompt injection tracked as LLM01 in the OWASP Top 10 for LLM Applications. This method bypasses security measures to inject malicious prompts into the large language model, causing it to access trusted data without the user's consent. Aim Labs detailed the technique in their report, demonstrating how an attacker could craft an email to trigger the data exfiltration automatically.

Microsoft's Patch Timeline

Aim Labs contacted Microsoft about the vulnerability in January 2025. Microsoft finalized a patch for EchoLeak in May 2025, addressing the flaw in its M365 Copilot service. Copilot integrates with Office apps and uses OpenAI's GPT models along with Microsoft Graph to personalize responses. The company has not disclosed any instances of the vulnerability being exploited in the wild.

What's Next

The discovery highlights the growing attack surface of AI-powered productivity tools, with security experts calling for deeper audits of RAG implementations. It remains unclear whether similar LLM Scope Violation risks exist in other AI assistants or whether further zero-click flaws await discovery.

1 source

Aim Labs researchers find first zero-click AI flaw in M365 Copilot, patched in May 2025