November 2025Unreviewed
EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System
Pavan Reddy, Aditya Sanjay Gujral
Proceedings of the AAAI Symposium Series
Abstract
Large language model (LLM) assistants are increasingly integrated into enterprise workflows, raising new security concerns as they bridge internal and external data sources. This paper presents an in-depth case study of EchoLeak (CVE-2025-32711), a zero-click prompt injection vulnerability in Microsoft 365 Copilot that enabled remote, unauthenticated data exfiltration via a single crafted email. By chaining multiple bypasses--evading Microsoft’s XPIA (Cross Prompt Injection Attempt) classifier,
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@inproceedings{reddy2025echoleak,
title = {{EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System}},
author = {Pavan Reddy and Aditya Sanjay Gujral},
year = {2025},
month = nov,
booktitle = {Proceedings of the AAAI Symposium Series},
doi = {10.1609/aaaiss.v7i1.36899},
url = {https://doi.org/10.1609/aaaiss.v7i1.36899}
}