A working self-replication path for prompt injection changes the threat model for any that reads user-supplied documents.
“Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier.”
Håkon Måløy
“We've seen plenty of hidden white-on-white text before - the kids are using it in their job applications now - but this is the first one I've seen that deliberately copies instructions to self-replicate itself.”
“It was responsibly disclosed to Microsoft who then had 144 days to work on a fix, but so far (unsurprisingly) there's no mitigation that covers the full class of attack.”
Checking sign-in…
Loading comments…