Program

/

CODE BLUE 2026

Time Table

ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping

Imagine uploading a document to an AI assistant and having your entire Microsoft 365 environment compromised. In this presentation, we reveal “Remote Prompt Execution” - an attack class where attackers execute arbitrary prompts on a victim’s session.

We walk through a full exploit chain starting with an LLM safety filter bypass to gain unprivileged execution in the sandbox. Next, we escalate privileges to root inside the container to unlock a hidden attack surface. We then exploit an unauthenticated internal daemon in the AKS Image Streaming service to achieve arbitrary file writes on the host, escaping the sandbox entirely.

Finally, we demonstrate how this grants interactive shell access over Copilot, exposing emails, calendar events, and files. We cover the discovery methodology, impact across Azure services, and MSRC disclosure.

** Important: Talk was/will be presented at Black Hat USA 2026.

  • Location :

    • Track 1(HALL B)

  • Category :

    • Technical

  • Share :

Speakers

  • オリー・ラハヴ の写真

    Ori Lahav

    オリー・ラハヴ

    Ori Lahav has spent over two decades of vulnerability research and peering under the hood of technologies. His security journey began in web security before going into embedded systems, operating system internals, electronics and hardware. A veteran of the competitive scene, he is a long-time player with the Pasten CTF team.