gaming
Researcher demonstrates Word doc can trigger self-replicating Copilot 'AI worm'
AI researcher Håkon Måløy showed that a Word document containing hidden JSON-formatted instructions can cause Copilot for Word to interpret and embed those instructions into edited output, creating a self-replicating 'AI worm.' The worm spreads when Copilot-assisted workflows treat infected documents as source material, and the original file does not need to remain present. Måløy disclosed the vulnerability to Microsoft in March, and the exploit remained reproducible at time of writing. The finding underscores broader security risks for agentic AI assistants on PCs and features like Windows Recall.
- A hidden JSON-formatted prompt embedded in a Word document can be interpreted by Copilot for Word as part of the user’s request and be copied into the resulting document.
- Documents that receive the hidden prompt become new carriers, enabling the malicious instructions to replicate across Copilot-assisted workflows; an attacker only needs to share a malicious document to initiate the spread.
- Håkon Måløy disclosed the vulnerability to Microsoft in March, but the attack vector remained reproducible at the time of writing.
- Previous agentic AI incidents have caused data loss—examples include an OpenClaw AI deleting a user’s emails and Replit’s assistant deleting a developer’s database—and security experts warn Windows Recall may not fully protect personal information on Copilot PCs.