Back Memeburn Microsoft Copilot SearchLeak Shows How AI Can Turn User Permissions Into Security Risks
A proof-of-concept attack showed hackers extracting 2FA codes from Copilot with one click . Microsoft patched SearchLeak ( CVE-2026-42824 ) before public disclosure . No confirmed in-the-wild exploitation has been reported. Here’s what happened, why AI access rules create security risks, and how to protect your organization. This matters for enterprise leaders because AI governance requires understanding permission inheritance .
Dolev Taler from Varonis Threat Labs discovered SearchLeak ( CVE-2026-42824 ) in mid-June 2026 . This discovery marks a shift from traditional malware to AI retrieval-layer attacks .
“We turned M365 Copilot into a one-click data exfiltration weapon. This is the first time an AI assistant has been exploited to steal enterprise data without requiring any user interaction beyond a single click.”
Copilot inherits user permissions, creating enterprise risk . Attackers exploited this to access organizational data. Microsoft patched the vulnerability on the backend without requiring user-side action. Security concerns are increasingly influencing AI deployment decisions.
The vulnerability exposed risks when AI agents sit between public web services and private enterprise data. The attack relied on indirect prompt injection . Attackers embedded instructions into a URL instead of having a user type a malicious prompt. Copilot processed attacker-controlled instructions within the retrieved content.
Three mechanisms worked together as part of a single attack chain. Parameter-to-prompt injection let attackers embed commands into the URL. An HTML streaming race condition let attackers extract data before security checks blocked it. A CSP bypass through Bing’s SSRF transmitted stolen data externally. Copilot operates with your access rights. Attackers forced the AI to retrieve data within your permission scope using timing flaws.
An illustrative scenario demonstrates the proof-of-concept outcome . A user clicks a link resembling “meeting-invite.com.” Copilot reads the inbox and extracts a 2FA code , then sends it externally. This illustrates what could happen under vulnerable conditions.
The vulnerability bypassed standard Data Loss Prevention (DLP) policies and sensitivity labels. Files marked “confidential” could have been exposed. DLP bypass undermines enterprise security controls. Attackers target these assets for account takeover and sensitive data access. Categories of data at risk:
Copilot Enterprise users were primarily affected. Copilot Business Chat and Copilot Personal may also be vulnerable, pending Microsoft confirmation. Organizations processing large volumes of sensitive data faced the highest risk. Word, Excel, PowerPoint, Teams, and Outlook served as potential conduits when Copilot Enterprise was integrated.
Large enterprises faced elevated exposure due to centralized Copilot deployments across multiple departments. Organizations with executives or finance teams using Copilot had higher concentrations of sensitive data accessible through the AI .
Exposure depended primarily on Copilot permissions, indexing scope, and deployment configuration. Organizations granting Copilot broad access to mailboxes, SharePoint sites, and OneDrive folders faced greater risk. Organizations with weak permission governance faced greater risk because Copilot could retrieve more sensitive content. Companies that deployed Copilot without auditing data access boundaries or configuring granular restrictions were most exposed during the vulnerability window.
Microsoft classified this as “max severity: critical” despite a CVSS score of 6.5 (medium) . Vendor severity ratings sometimes differ from CVSS scores because they reflect different priorities. CVSS focuses on technical exploitability . Microsoft assesses business impact . Enterprise-wide account takeover enables attackers to access email, cloud storage, and corporate systems. Security teams prioritize business impact over CVSS scores. That justifies the critical classification .
Microsoft patched the vulnerability on the backend June 4, 2026 . Enterprises should treat this as a baseline for future AI security planning. SearchLeak demonstrates that AI retrieval-layer risks will persist across platforms. Traditional DLP policies can fail against AI retrieval attacks . Least-privilege access principles are essential for AI assistants. Recommendations include:
AI assistants are gaining access to more enterprise systems . Retrieval-layer vulnerabilities need monitoring. Security teams balance automation benefits with AI abuse risks. Enterprise AI governance is evolving to address retrieval-layer risks across products. The SearchLeak lesson extends to enterprise AI systems beyond Microsoft.
SearchLeak showed enterprise AI can expose data through one click from permission inheritance . Success means balancing productivity with security. Mature governance means permission oversight leads adoption. Enterprises prioritizing this will advance AI adoption. Others may delay deployment until security concerns are resolved.
Jennie is a tech and AI writer at Memeburn, where she turns complex engineering into stories everyone can enjoy. With over two years of experience as a software engineer, she has built everything from smart automation tools to large-scale data systems. Because she knows firsthand how software is created, she has a knack for breaking down tricky tech trends and AI breakthroughs into clear, natural language. At Memeburn, Jennie uses her builder’s perspective to deliver fresh, insightful coverage on the latest in tech news, making advanced developer concepts accessible and engaging for all readers.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
