Breaking Down EchoLeak: The First Zero-Click AI Vulnerability in Microsoft 365 Copilot In a groundbreaking discovery, Aim Labs has uncovered EchoLeak, a critical zero-click vulnerability that affects Microsoft 365 Copilot (M365 Copilot), Microsoft’s RAG-based AI-powered chatbot. This newly identified vulnerability is one of the most significant threats to the security of AI applications, as it enables attackers to automatically exfiltrate sensitive data from an organization’s internal environment without requiring any user interaction. What Is EchoLeak? EchoLeak is a novel attack chain that exploits the inherent design flaws in retrieval-augmented generation (RAG) AI systems, such as M365 Copilot. Unlike traditional vulnerabilities, which typically require user interaction (clicks, downloads, or input), EchoLeak operates silently and automatically, executing its exploit with zero-clicks. This means attackers can target Microsoft’s internal AI model and exfiltrate proprietary and confidential data from organizational environments like email, The attack relies on a technique called "LLM Scope Violation," a term coined by Aim Labs to describe how attackers can manipulate untrusted inputs (such as an email) to make the LLM (Large Language Model) access and retrieve privileged, sensitive data from the model’s context, without the user’s consent. How the Attack Works: A Step-by-Step Breakdown The EchoLeak attack unfolds in several distinct steps, leveraging traditional vulnerabilities (like Content-Security-Policy (CSP) bypasses) alongside newer, AI-specific flaws (like prompt injection). Step 1: XPIA Bypass Microsoft deploys XPIA (cross-prompt injection attack) classifiers to block malicious inputs aimed at M365 Copilot. However, the attackers found a way to bypass this safeguard by crafting the email as if it were intended for the recipient (not the LLM). This subtle method avoids detection by XPIA, allowing the malicious email to pass through undetected. Step 2: Link Redaction Bypass M365 Copilot typically redacts external links from its chat interface for security purposes. However, the researchers discovered that reference-style markdown links were not properly redacted, enabling attackers to craft hidden links that still exfiltrated sensitive data when accessed by the LLM. Step 3: Image Redaction Bypass Building on the link bypass, the researchers then explored the possibility of exfiltrating data through images. By embedding images with external URLs in markdown format, they found that M365 Copilot could still fetch and display images from attacker-controlled servers, bypassing the redaction mechanism in place for links. Step 4: CSP Bypass Using SharePoint and Teams In the next phase, attackers discovered a Content-Security-Policy (CSP) bypass through SharePoint and Teams. The attackers crafted a request that used SharePoint’s internal API to fetch data on their behalf, enabling them to pull sensitive information from the M365 context without user interaction. Microsoft Teams was also exploited as an alternative, bypassing the need for the victim to actively engage with malicious content. LLM Scope Violation: The Heart of EchoLeak At the core of this attack is the LLM Scope Violation, a violation of the Principle of Least Privilege in AI models. Typically, the AI model should not have access to privileged organizational data unless explicitly permitted. However, through malicious prompt injections (contained in the attacker’s email), the LLM was manipulated into accessing and exposing highly sensitive information from the context, an exploit that is impossible without breaking the model’s security design. This form of indirect prompt injection is difficult to detect because the email is structured to look innocent, even though it contains harmful instructions for the LLM. This makes it an especially dangerous form of attack since conventional detection systems might miss it entirely. Weaponizing EchoLeak: RAG Spraying and LLM Scope Violation Once the attack chain is established, the adversary must ensure that the malicious email gets retrieved by the M365 Copilot. This is where RAG spraying comes into play. Attackers can either send multiple malicious emails or send a long email that is chunked into parts. Each chunk targets a different point in the latent space of the AI, maximizing the chances of one of them being retrieved by the system when queried on related topics. Moreover, by injecting instructions to pull the most sensitive information from the LLM’s context (like internal emails, corporate secrets, and proprietary data), the attacker can exfiltrate valuable data even if the email appears to be innocuous on the surface. EchoLeak's Far-Reaching Impact: A Wake-Up Call for AI Security EchoLeak is a first-of-its-kind vulnerability that sheds light on a growing risk: the exploitation of internal AI model vulnerabilities to carry out data exfiltration attacks. It has wide implications, especially as