Skip to main content
VerifiedExfiltration

EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot

Aim Labs disclosed a chain in which an inbound email caused Microsoft 365 Copilot to leak data from the user's own context with no click at all. Microsoft tracked it as CVE-2025-32711, an AI command injection information disclosure flaw rated critical, and states the vulnerability was fully mitigated on its own service with no action for customers.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0007
Kind
Exfiltration
Jurisdiction
United States
Last verified
Added
  • Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
  • Microsoft classifies the issue as an information disclosure vulnerability in M365 Copilot and rates it critical.
  • Infosecurity Magazine reports the researchers described it as the first zero click AI vulnerability, in a report published on 11 June 2025.
  • The researchers named the technique an LLM scope violation, where untrusted input causes the model to reach trusted data it should not.
  • The researchers contacted Microsoft in January 2025 and the patch was finalised in May 2025, according to the same report.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Delegation, Human approval, Revocation, Accountability, Logging and audit. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
An unauthenticated external sender reached the agent's context and no sender identity weighted the instruction.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
AuthorizationSilent
Untrusted content effectively authorized itself to reach the tenant data the user could see.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
DelegationSilent
The assistant applied the user's full retrieval scope to content that arrived from a stranger.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
Human approvalSilent
The defining property is that there was no click, so no approval step existed to hold.Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerability, secondary source, 13 June 2025.
RevocationStated
Microsoft mitigated the flaw on its own service, which removed the capability from every tenant at once with no customer action.Microsoft Security Response Center, CVE-2025-32711, primary source, 11 June 2025.
AccountabilityStated
Microsoft issued a CVE with a published score and states it did so for transparency even though no customer action was required.Microsoft Security Response Center, CVE-2025-32711, primary source, 11 June 2025.
Logging and auditOpen
The public record does not say what a tenant's own telemetry would have shown.

Figures

Every number, with who measured it and when

  1. 9.3 CVSS base score

    CVSS base score Microsoft assigned to CVE-2025-32711

    Microsoft Security Response Center, CVE-2025-32711, primary source, as of .

What it changes

For a team deploying an agent

A copilot with connectors is a retrieval agent with your whole tenant in reach, and untrusted email is an instruction channel into it. The control that was missing is authorization: content that arrives from outside the organisation must not inherit the reading rights of the person it was sent to. Ask your vendor what separates untrusted content from instructions, and what blocks the outbound channel when that separation fails.

Sources

What this record was verified against

  1. Microsoft Security Response Center, CVE-2025-32711Primary · 11 June 2025
  2. Infosecurity Magazine, Microsoft 365 Copilot zero click vulnerabilitySecondary · 13 June 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0007 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), echoleak, a zero click chain that pulled tenant data out of microsoft 365 copilot.
APA
GAGE (Global Academy of Generative-AI Education). (2026). EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration
MLA
"EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration.
Chicago
GAGE (Global Academy of Generative-AI Education). "EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0007-echoleak-microsoft-365-copilot-zero-click-exfiltration

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.