Copilot zero-click — EchoLeak class

Copilot zero-click — EchoLeak class

TL;DR: A single crafted email coerces M365 Copilot to summarise and exfil OneDrive / SharePoint content via trusted-domain image rendering (CVE-2025-32711).

Stub — to be filled in.

What it is

TODO

Preconditions / where it applies

TODO

Technique

TODO

Detection and defence

TODO

References

  • TODO