Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

EchoLeak, tracked as CVE-2025-32711, was a reported vulnerability in Microsoft 365 Copilot in which a crafted email could prompt Copilot to disclose sensitive information without the recipient clicking an attacker-controlled link. A technical paper by Pavan Reddy and Aditya Sanjay Gujral describes the attack chain and says Microsoft deployed a server-side fix in May 2025, before the issue was publicly disclosed in June. The paper says customers did not need to take action to install a patch.

How the reported zero-click attack worked

EchoLeak relied on indirect prompt injection: malicious instructions were placed in an email that Copilot might process while retrieving context to answer a user. In the paper’s account, Copilot could incorporate sensitive organizational information into a generated response, then include an image or reference link that carried information outward. Automatic fetching of that resource, together with a Microsoft Teams proxy path, could enable exfiltration without a person following the link.

“Zero-click” describes the lack of a required click on an attacker-controlled link. It does not mean the attack happened without Copilot processing the crafted email. The paper characterizes the chain as crossing several defenses, including prompt-injection classification, link redaction, and content-security policy controls. This is a conceptual summary, not an exploit procedure.

What the vulnerability did—and did not—mean

  • It was a specific reported flaw: EchoLeak refers to CVE-2025-32711 in Microsoft 365 Copilot, rather than every risk associated with generative AI or prompt injection.
  • The reported input was an email: The attack used indirect instructions in content Copilot could ingest, not direct access to a victim’s Copilot account.
  • It was not a conventional link-click attack: Automatic resource fetching was central to the paper’s account of how data could leave.
  • It should not be conflated with later one-click reports: The zero-click description is specific to the EchoLeak chain documented in the paper.

Reported disclosure, fix, and customer action

The technical paper says the researchers privately reported the issue to Microsoft’s Security Response Center. It reports that Microsoft deployed a server-side fix in May 2025, before public disclosure on June 11, 2025, and that no customer action was required. These timeline and remediation details are attributed to the paper; they are not a substitute for checking Microsoft’s CVE record for a vendor-published account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Because the described remediation was server-side, this report does not establish a customer-installed patch or a product purchase as the EchoLeak fix. Nor does the historical account establish that the vulnerability remains exploitable after the reported remediation.

What Microsoft 365 administrators should do now

Microsoft’s current security guidance describes Copilot as using Microsoft 365 identity and access controls to access data users are authorized to see. Microsoft also warns that overshared or poorly governed data can affect Copilot results and increase risk. Those controls matter for the broader security of a tenant; they should not be presented as what prevented EchoLeak, which the paper describes as a flaw in how malicious instructions and generated output crossed trust boundaries.

Review exposure and governance

Microsoft documents a Copilot security dashboard with insights and controls related to data-loss prevention, oversharing, and compliance. Its guidance says Global Reader is required to view the dashboard section, while AI Administrator is required to make changes. Microsoft notes that dashboard details can change, so administrators should confirm current availability, labels, and role requirements in the live documentation.

Apply preventive data controls

Microsoft’s guidance also covers sensitivity labels and encryption, SharePoint and OneDrive discovery and sharing controls, and Purview capabilities for data-loss prevention. These measures can help govern what information is available and how it is handled; they are ongoing tenant controls, not the reported server-side EchoLeak remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use auditing and retention for oversight

Microsoft documents audit and retention capabilities for Copilot interaction data through Purview. Administrators can consult Microsoft’s current architecture guidance to understand what is available for their configuration and compliance needs. These capabilities support oversight and governance rather than replacing access controls or the historical service-side fix.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Sources and scope

The technical description and patch timeline above come from Pavan Reddy and Aditya Sanjay Gujral’s paper, published September 6, 2025. Current administrator guidance comes from Microsoft Learn: Security for Microsoft Copilot, updated September 25, 2026, and How data is protected and audited in Microsoft 365 and Microsoft Copilot, updated August 18, 2026. The paper’s technical and historical claims are attributed to that paper because a directly accessible Microsoft advisory was not established here.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.