Threat · curated 7 Sep 2026

Copilot Cowork Sandbox Bypass Gives Attackers Remote Control

Coverage timeline

7 Sep 2026promptarmor.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Microsoft Copilot Cowork's sandbox bypass shows how a deployed enterprise AI agent can be turned into a remote-controlled data-exfiltration channel through prompt injection or a malicious Skill, reaching the user's connected corporate services.

PromptArmor disclosed a vulnerability in Microsoft Copilot Cowork, an M365 agent that acts with the user's permissions, where a sandbox bypass allowed untrusted network requests. When triggered via prompt injection or a malicious uploaded Skill, the flaw let attackers establish a command-and-control loop to execute commands and exfiltrate data from Outlook, SharePoint, plugins, and chat history — even after the user clicked stop. The issue was reported to Microsoft on June 24, 2026 and mitigated as of August 19, 2026.