Page 1 of 1

Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction

Posted: Sun Jun 15, 2025 6:26 am
by Shane1145
A novel attack technique named EchoLeak has been characterized as a "zero-click" artificial intelligence (AI) vulnerability that allows bad actors to exfiltrate sensitive data from Microsoft 365 (M365) Copilot's context sans any user interaction.

The critical-rated vulnerability has been assigned the CVE identifier CVE-2025-32711 (CVSS score: 9.3). It requires no customer action and has been already addressed by Microsoft. There is no evidence that the shortcoming was exploited maliciously in the wild.

https://thehackernews.com/2025/06/zero- ... poses.html