Skip to content
PromptArmor Threat Intelligence·· Aug 24, 2026PickAI score80

Microsoft Copilot Cowork sandbox bypass let attackers take remote control

Copilot Cowork Sandbox Bypass Gives Attackers Remote Control

AI summary

PromptArmor disclosed a vulnerability in Microsoft Copilot Cowork that allowed a bypass of the sandbox, letting attacker servers send commands that run in the sandbox and return results. The attack could be triggered through a prompt injection or a malicious bundled script in a user-uploaded Skill, and it could read data from Outlook, SharePoint, plugins, and chat history. The issue was reported to Microsoft on June 24, 2026 and confirmed mitigated on August 19, 2026.

Why it matters

The report traces how a malicious bundled script in an uploaded Skill escaped the sandbox and kept running after the stop button was pressed, a concrete case of agent security failure.

Read the original promptarmor.com

Source: PromptArmor Threat Intelligence · promptarmor.com