The scariest word in the incident ledger is not “injection.” It is “zero-click.”
Prompt injection was, for years, argued about as a theoretical risk. Then, in a single stretch, three disclosures removed the word “theoretical.” In each one, the exfiltration happened without the victim doing anything except using the product normally.
EchoLeak: one email, no clicks
EchoLeak (CVE-2025-32711) is, in the authors’ own framing, the first real-world zero-click prompt injection exploit in a production LLM system. A single crafted email to Microsoft 365 Copilot triggered remote, unauthenticated data exfiltration. The paper, by Pavan Reddy and Aditya Sanjay Gujral (arXiv:2509.10540), walks through chained bypasses: evading Microsoft’s cross-prompt-injection classifier, circumventing link redaction with reference-style Markdown, and abusing a Teams proxy already allowed by the content security policy. The result was full escalation across LLM trust boundaries with no user interaction.
That last detail matters. Copilot was not tricked by a malicious person sending it a prompt. It was tricked by an object, an email, that it was asked to process.
Notion: the PDF that read the workspace
In September 2025, shortly after Notion shipped AI agents in its 3.0 release, researchers found that a PDF with hidden instructions could steer Notion’s AI to collect the text of a workspace document, encode it into a URL, and load it as an “image” from an attacker-controlled domain. The data went out through the AI’s own web-fetch capability. PromptArmor documented the chain; Notion later said it had upgraded its detection systems.
The instructive part is the vector: a document the user wanted the agent to read. The attacker did not defeat a permission. The agent’s legitimate permission was the attack surface.
A calendar invite as an attack
The same pattern appeared in Google’s ecosystem: a malicious calendar invitation could bypass authorization safeguards, so that a harmless “what’s on my calendar?” query caused private meeting details to be summarized into an event visible to the attacker. No interaction beyond the query. The object was the payload.
What connects them
Each incident shares a structure that a content filter cannot reliably catch:
- The malicious instruction arrives inside data the user asked the agent to process: an email, a PDF, a calendar event.
- The agent’s legitimate capability (read mail, summarize documents, query a calendar) becomes the exfiltration channel.
- The user’s trust in the object is transferred, unwittingly, to the instructions hidden in it.
A classifier asks “is this content malicious?” and must get it right every time, against an attacker who can re-encode the same instruction a thousand ways. The alternative is to ask a different question: does the action this content is steering the agent toward fall within the authority the session was granted? That question does not depend on detecting the instruction at all.
Sources accessed 2026-09-20. EchoLeak: arXiv:2509.10540 (PRIMARY). Notion: PromptArmor and The Decoder (SECONDARY). The calendar-invite case is a community-documented case study in awesome-agent-failures.