dotsagent.io
Language:English
CVE-2025-32711

EchoLeak: zero-click data theft from Microsoft 365 Copilot

One crafted email made Microsoft 365 Copilot leak data without the user clicking anything. Aim Security reported it as EchoLeak; Microsoft fixed it server-side.

What happened

EchoLeak, reported by Aim Security and tracked as CVE-2025-32711, was a zero-click data exfiltration flaw in Microsoft 365 Copilot. The attacker only had to send a crafted email. Once Copilot read that email while working for the user, its hidden instructions took effect.

The data left through URLs in Copilot's output that loaded automatically, so no click was needed. Microsoft fixed the issue on the server side.

Why it worked

Copilot combined private mailbox and document data, untrusted inbound email, and output that was rendered and fetched without user action. Auto-loaded images and links turned the model's answer into an outbound request that carried the data.

What to do

  • Don't auto-load images or links in model output that point to external domains.
  • Set a strict Content Security Policy on any page that renders model output.
  • Treat inbound email and shared documents as untrusted content, even inside your own tenant.
  • Keep agents that read external mail away from data the task doesn't need.

Treat model output as untrustedBreak the lethal trifecta

Work through the security checklist →

Sources

  1. nvd.nist.gov/vuln/detail/cve-2025-32711

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026