you are viewing a single comment's thread
view the rest of the comments
[–] 154 points 2 months ago (10 children)

The tl;dr:

  1. Prompt inject a malicious instruction in a word document that instructs the AI to copy this instruction to other documents as part of the payload.

  2. Dumb user downloads and opens the document with copilot enabled, abd ignores the large suspicious white blank page that totally doesnt look like a hidden giant injection attack.

  3. Thats it pretty much it.

Copilot will get injection attacked because the prompt is super huge and at the end of the document, so its prior instructions start to fuzzy out.

Then it'll go "okey doke" and start copying the prompt injection attack payload to a bunch of other documents.

The fix is stupid simple... copilot should just be prompting the user for permission if it ever edits a file other than the one that is open. Im surprised that isnt already the case...?

It certainly is already the case for copilot in vscode.

  • source
  • hideshow 10 child comments
  • [–] 9 points 2 months ago (2 children)

    Considering people's Word formatting skills, a random blank page is not suspicious

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 months ago

    Word's interface doesn't help. Default view gives you almost zero information on section breaks, and even if you turn on formatting marks they behave in an unintuitive manner and there's some edge cases where Word will still generate a new page after a continuous section break unless you set the font size after the break to 1.

  • source
  • parent
  • load more comments (1 reply)
  • load more comments (8 replies)