Preliminary research
ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
A malicious document tells Microsoft Copilot to run gzip-packed Python in its analysis sandbox, which then reaches an unauthenticated internal service on the host network; its /config endpoint takes a name that traverses out of the config directory, so files land anywhere on the host. Writing a containerd hosts.toml plus an ld.so.preload symlink plants a root backdoor, escaping the sandbox and giving the attacker an interactive prompt channel into the victim's Copilot.
Record
- Researcher
- Ori Lahav
- Published by
- i.blackhat.com
- Format
- Whitepaper
- Topic
- AI
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ori Lahav, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .