EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
Aim Labs disclosed a chain in which an inbound email caused Microsoft 365 Copilot to leak data from the user's own context with no click at all. Microsoft tracked it as CVE-2025-32711, an AI command injection information disclosure flaw rated critical, and states the vulnerability was fully mitigated on its own service with no action for customers.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0007
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
- Microsoft classifies the issue as an information disclosure vulnerability in M365 Copilot and rates it critical.
- Infosecurity Magazine reports the researchers described it as the first zero click AI vulnerability, in a report published on 11 June 2025.
- The researchers named the technique an LLM scope violation, where untrusted input causes the model to reach trusted data it should not.
- The researchers contacted Microsoft in January 2025 and the patch was finalised in May 2025, according to the same report.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Delegation, Human approval, Revocation, Accountability, Logging and audit. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- An unauthenticated external sender reached the agent's context and no sender identity weighted the instruction.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
- AuthorizationSilent
- Untrusted content effectively authorized itself to reach the tenant data the user could see.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
- DelegationSilent
- The assistant applied the user's full retrieval scope to content that arrived from a stranger.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
- Human approvalSilent
- The defining property is that there was no click, so no approval step existed to hold.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
- RevocationStated
- Microsoft mitigated the flaw on its own service, which removed the capability from every tenant at once with no customer action.Microsoft Security Response Center, CVE-2025-32711, primary source, 11 June 2025.
- AccountabilityStated
- Microsoft issued a CVE with a published score and states it did so for transparency even though no customer action was required.Microsoft Security Response Center, CVE-2025-32711, primary source, 11 June 2025.
- Logging and auditOpen
- The public record does not say what a tenant's own telemetry would have shown.
Figures
Every number, with who measured it and when
- 9.3 CVSS base score
CVSS base score Microsoft assigned to CVE-2025-32711
Microsoft Security Response Center, CVE-2025-32711, primary source, as of .
What it changes
For a team deploying an agent
A copilot with connectors is a retrieval agent with your whole tenant in reach, and untrusted email is an instruction channel into it. The control that was missing is authorization: content that arrives from outside the organisation must not inherit the reading rights of the person it was sent to. Ask your vendor what separates untrusted content from instructions, and what blocks the outbound channel when that separation fails.
Sources
What this record was verified against
- Microsoft Security Response Center, CVE-2025-32711Primary · 11 June 2025
- Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerabilitySecondary · 13 June 2025
Related
Records that sit beside this one
ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
United States · verified 15 September 2026
The research states that the compromised agent accesses connected lists and sends sensitive customer data to an attacker controlled email address.
SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
United States · verified 15 September 2026
The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session
United States · verified 15 September 2026
The research states the injected instruction remains active in every future session for that user unless the user manually navigates to memory settings and deletes it.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0007 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), echoleak, a zero click chain that pulled tenant data out of microsoft 365 copilot.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration
- MLA
- "EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.