Bleepingcomputer
Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat Labs, the attack exploits a chain of three vulnerabilities: parameter-to-prompt injection, an HTML rendering race condition, and a server-side request forgery (SSRF) via Bing. The attack targets emails, calendar entries, and files stored in OneDrive and SharePoint, enabling the theft of sensitive information such as MFA codes and access tokens. Microsoft rated the vulnerability as critical and patched it on June 4, 2026, requiring no action from users. The flaw is particularly dangerous as it bypasses traditional security measures due to the use of a legitimate Microsoft domain. No evidence of in-the-wild exploitation has been reported.
Key Points: • SearchLeak allows one-click data exfiltration from Microsoft 365 Copilot Enterprise. • The attack exploits three vulnerabilities, including parameter-to-prompt injection and SSRF. • Microsoft has patched the vulnerability, but users should remain vigilant against suspicious links.