Microsoft Copilot Cowork Exfiltrates Files
Microsoft Copilot Cowork, an agentic AI system, was found to allow data exfiltration by sending emails to a user's inbox without approval. These messages could contain external images that trigger network requests, leaking data when opened. Additionally, prompt injection could expose pre-authenticated OneDrive download links, enabling attackers to download files.