CamoLeak Attack Exploits GitHub Copilot for Data Exfiltration
Summary
Hide ▲
Show ▼
A new proof-of-concept (PoC) attack, dubbed 'CamoLeak,' demonstrates how GitHub Copilot can be exploited to exfiltrate sensitive user data through a series of complex steps. The attack leverages hidden comments and image tags to bypass GitHub's security features, allowing an attacker to steal small amounts of data, such as passwords or private keys, without detection. The attack involves two main phases: prompt injection to influence Copilot's output and a bypass of GitHub's Camo security feature using invisible image tags. GitHub has since disabled image rendering in Copilot chat to mitigate this risk. The technique is not suitable for large-scale data exfiltration but can selectively leak sensitive information within minutes.
Timeline
-
09.10.2025 22:56 1 articles · 12h ago
CamoLeak Attack Demonstrates Data Exfiltration via GitHub Copilot
A new proof-of-concept (PoC) attack, dubbed 'CamoLeak,' shows how GitHub Copilot can be exploited to exfiltrate sensitive user data. The attack involves using hidden comments and image tags to bypass GitHub's Camo security feature, allowing an attacker to steal small amounts of data without detection. GitHub has disabled image rendering in Copilot chat to prevent real attackers from using this technique.
Show sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56
Information Snippets
-
The CamoLeak attack exploits GitHub Copilot to exfiltrate sensitive user data through hidden comments and image tags.
First reported: 09.10.2025 22:561 source, 1 articleShow sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56
-
The attack involves two phases: prompt injection to influence Copilot's output and a bypass of GitHub's Camo security feature.
First reported: 09.10.2025 22:561 source, 1 articleShow sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56
-
GitHub's Camo feature acts as a secure proxy for third-party images, breaking direct links between users and hosting sites.
First reported: 09.10.2025 22:561 source, 1 articleShow sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56
-
The attacker uses invisible image tags to represent ASCII characters, encoding sensitive data as sequences of image requests.
First reported: 09.10.2025 22:561 source, 1 articleShow sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56
-
GitHub has disabled image rendering in Copilot chat to prevent real attackers from using the CamoLeak trick.
First reported: 09.10.2025 22:561 source, 1 articleShow sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56
-
The attack is not suitable for large-scale data exfiltration but can selectively leak sensitive information within minutes.
First reported: 09.10.2025 22:561 source, 1 articleShow sources
- GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data — www.darkreading.com — 09.10.2025 22:56