Ninety days is the industry standard for coordinated disclosure. Håkon Måløy gave Microsoft ninety on a Copilot flaw, extended it twice, and published on Tuesday at day 144 with the attack still working.
The attack is a worm made of prose. Instructions buried in one Word document get copied into the documents Copilot subsequently generates or edits, and each of those becomes a new carrier. No macro. No executable. No user error past opening a file. Morris II demonstrated the same self-replication inside email assistants; this is the version that rides ordinary document workflows — the ones where somebody forwards the deck, not the ones where somebody clicks the attachment.
Coordinated disclosure rests on a premise nobody bothers to state: that a patch is waiting at the end of the clock. The deadline is leverage, and leverage assumes the vendor can act. This is the case where the premise failed outright. Microsoft's status, as Måløy reports it, is that testing reproduced the attack with all current mitigations deployed. Two attempts to close the class, one of them a model upgrade, did not.
That isn't a weak fix. It's the absence of anything fix-shaped to ship. An assistant earns its keep by reading email, documents, and web pages an attacker may control, which means that content lands in the same context window as the system instructions and the user's request, participating in the same computation. Måløy's framing of why a filter can't rescue this is the sharpest sentence in the report:
The content being inspected participates in the act of inspection. Relying on the model to detect XPIAs therefore resembles asking an interpreter to execute an untrusted program to determine whether that program is safe to execute.En Klype Salt
Push the check outward and you need a detector with semantic reach equal to the model it guards, which in practice means another model, which then needs guarding. LLMs all the way down.
The obvious objection is that this is a vendor slow-walking an inconvenient bug, and Måløy forecloses it himself. The memory and email-body vectors from Parts 1 and 2 were mitigated outright. He credits Microsoft with "continued and substantive effort on a genuinely difficult problem," and says he knows of no complete mitigation for this class in any comparable product today. The vendor performed. The institution is what didn't fit.
The vendor performed. The institution is what didn't fit.
So he did the only thing the calendar left him: disclosed at the class level rather than the payload level, on the reasoning that defenders cannot reduce exposure to a risk they are unaware of. That is not a deadline doing its usual work. It is a different instrument wearing the same name — notice, not leverage. And the deliverable changes with it. There is no KB number to push through change management. There is a habit: read what the assistant wrote before you forward it, and treat any document that has passed through Copilot as attacker-reachable until you've looked.
Ninety days was always a threat with a repair on the other side of it. Close this, or I tell everyone. Måløy told everyone. At day 144 there was nothing else the clock could buy.