• Sources: primary, discussion
  • Summary: PromptArmor reports that Microsoft Copilot Cowork was vulnerable to a persistent attacker command loop established inside its sandbox, and that the user-facing stop button did not end the loop. The escape used a file-sync service running outside the sandbox that accepted an attacker-supplied URL, reachable from ordinary Skill code a user downloaded. The disclosure timeline gives the report to Microsoft as 2026-06-24, and states that Microsoft confirmed on 2026-08-19 that the issue had been mitigated, so the write-up describes a fixed condition rather than a live one. Affected versions do not apply, because Cowork is a hosted service with no user-visible version and the mitigation was server-side.
  • Why it matters: The network isolation the agent's threat model depended on was reachable from ordinary Skill code, so sandboxing the agent process does not bound the agent when adjacent services are not sandboxed with it.

send feedback on this story