Threat · curated 7 Sep 2026
Copilot Cowork Sandbox Bypass Gives Attackers Remote Control
First reported promptarmor.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Microsoft Copilot Cowork's sandbox bypass shows how a deployed enterprise AI agent can be turned into a remote-controlled data-exfiltration channel through prompt injection or a malicious Skill, reaching the user's connected corporate services.
PromptArmor disclosed a vulnerability in Microsoft Copilot Cowork, an M365 agent that acts with the user's permissions, where a sandbox bypass allowed untrusted network requests. When triggered via prompt injection or a malicious uploaded Skill, the flaw let attackers establish a command-and-control loop to execute commands and exfiltrate data from Outlook, SharePoint, plugins, and chat history — even after the user clicked stop. The issue was reported to Microsoft on June 24, 2026 and mitigated as of August 19, 2026.