Skip to content
Read the original: PromptArmor Threat Intelligence· Published Pick80/100AI score80/100

Microsoft Copilot Cowork sandbox bypass let attackers take remote control

Original titleCopilot Cowork Sandbox Bypass Gives Attackers Remote Control

AISummary

PromptArmor disclosed a vulnerability in Microsoft Copilot Cowork that allowed a bypass of the sandbox, letting attacker servers send commands that run in the sandbox and return results.

The attack could be triggered through a prompt injection or a malicious bundled script in a user-uploaded Skill, and it could read data from Outlook, SharePoint, plugins, and chat history.

The issue was reported to Microsoft on June 24, 2026 and confirmed mitigated on August 19, 2026.

AIWhy it matters

The report traces how a malicious bundled script in an uploaded Skill escaped the sandbox and kept running after the stop button was pressed, a concrete case of agent security failure.

Read the original promptarmor.com

Source: PromptArmor Threat Intelligence · promptarmor.comPublished · added here