Skip to content
Search
paperNovember 2025Unreviewed

EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System

Pavan Reddy, Aditya Sanjay Gujral

Proceedings of the AAAI Symposium Series

Abstract

Large language model (LLM) assistants are increasingly integrated into enterprise workflows, raising new security concerns as they bridge internal and external data sources. This paper presents an in-depth case study of EchoLeak (CVE-2025-32711), a zero-click prompt injection vulnerability in Microsoft 365 Copilot that enabled remote, unauthenticated data exfiltration via a single crafted email. By chaining multiple bypasses--evading Microsoft’s XPIA (Cross Prompt Injection Attempt) classifier,

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@inproceedings{reddy2025echoleak,
  title = {{EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System}},
  author = {Pavan Reddy and Aditya Sanjay Gujral},
  year = {2025},
  month = nov,
  booktitle = {Proceedings of the AAAI Symposium Series},
  doi = {10.1609/aaaiss.v7i1.36899},
  url = {https://doi.org/10.1609/aaaiss.v7i1.36899}
}