{"id":75242,"date":"2026-06-16T08:07:11","date_gmt":"2026-06-16T08:07:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/75242\/"},"modified":"2026-06-16T08:07:11","modified_gmt":"2026-06-16T08:07:11","slug":"searchleak-vulnerability-hits-microsoft-365-copilot-users","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/75242\/","title":{"rendered":"SearchLeak Vulnerability Hits Microsoft 365 Copilot Users"},"content":{"rendered":"<p>A newly disclosed\u00a0SearchLeak\u00a0vulnerability\u00a0in\u00a0Microsoft 365 Copilot Enterprise\u00a0exposed a critical pathway for attackers to steal sensitive organizational data through a specially crafted URL. The flaw chain, now tracked as\u00a0CVE-2026-42824, was patched by Microsoft earlier this month and assigned a critical severity rating due to its potential impact.<\/p>\n<p>Security researchers at Varonis discovered the issue by combining three separate weaknesses that, on their own, posed limited risk. Together, however, they enabled attackers to silently extract emails, calendar information, SharePoint documents, OneDrive files, and other indexed enterprise content accessible through\u00a0Microsoft 365 Copilot Enterprise.<\/p>\n<p>How the\u00a0SearchLeak\u00a0Vulnerability Worked\u00a0<\/p>\n<p>According to the <a href=\"https:\/\/www.varonis.com\/blog\/searchleak\" target=\"_blank\" rel=\"nofollow noopener\">researchers<\/a>, the\u00a0SearchLeak\u00a0vulnerability\u00a0combined an AI-specific flaw known as Parameter-to-Prompt Injection (P2P) with two traditional web security issues: an HTML rendering race condition and a server-side request forgery (SSRF) vulnerability involving Bing.\u00a0<\/p>\n<p>The first stage exploited the search function of\u00a0Microsoft 365 Copilot Enterprise, where the \u201cq\u201d URL parameter was passed directly to Copilot as an executable prompt. Instead of being treated as a simple search query, attacker-controlled input could be interpreted as instructions.\u00a0<\/p>\n<p>Researchers\u00a0demonstrated\u00a0that a malicious URL could instruct <a href=\"https:\/\/thecyberexpress.com\/copilot-recall-cybersecurity\/\" target=\"_blank\" rel=\"noopener nofollow\">Copilot<\/a> to search a victim\u2019s mailbox, retrieve email titles or other sensitive content, and embed the extracted data inside an image URL without requiring any user interaction beyond a click.\u00a0<\/p>\n<p>Chaining Three Flaws into One Attack\u00a0<\/p>\n<p>The second stage relied on an HTML rendering race condition. While Microsoft\u00a0attempted\u00a0to neutralize potentially dangerous HTML by wrapping responses inside code blocks, that protection occurred only after Copilot completed generating its response. During the streaming phase, raw HTML, including image tags, could briefly\u00a0render\u00a0and trigger outbound requests before sanitization took effect.\u00a0<\/p>\n<p><a href=\"https:\/\/cyble.com\/resources\/research-reports\/\" aria-label=\"report-ad-banner\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" alt=\"report-ad-banner\" data-lazy- data-lazy- width=\"1200\" height=\"178\" data-lazy-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/report-ad-banner.webp\"\/><\/a><\/p>\n<p>The final\u00a0component\u00a0of the\u00a0SearchLeak\u00a0vulnerability\u00a0involved a Content <a class=\"wpil_keyword_link\" href=\"https:\/\/thecyberexpress.com\/\" title=\"Security\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"28716\" rel=\"nofollow noopener\" target=\"_blank\">Security<\/a> Policy bypass through Bing. Since Bing <a href=\"https:\/\/thecyberexpress.com\/why-ai-native-cybersecurity-matters\/\" target=\"_blank\" rel=\"noopener nofollow\">domains<\/a> were allowlisted, attackers\u00a0leveraged\u00a0Bing\u2019s image search endpoint, which performs server-side fetching of image URLs. By embedding stolen <a class=\"wpil_keyword_link\" href=\"https:\/\/thecyberexpress.com\/what-is-data\/\" title=\"data\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"28719\" rel=\"nofollow noopener\" target=\"_blank\">data<\/a> within those URLs, Bing unknowingly acted as a proxy,\u00a0forwarding\u00a0the information to attacker-controlled servers.\u00a0<\/p>\n<p>As described by Varonis, the attack required no plugins, elevated privileges,\u00a0additional\u00a0clicks, or suspicious domains. Victims only needed to open a trusted Microsoft link.\u00a0<\/p>\n<p>Potential Impact of CVE-2026-42824\u00a0<\/p>\n<p>Because\u00a0Microsoft 365 Copilot Enterprise\u00a0operates\u00a0with the user\u2019s existing permissions, successful exploitation of\u00a0CVE-2026-42824\u00a0effectively granted attackers access to whatever information the targeted employee could access.\u00a0<\/p>\n<p>Potentially exposed data included email content, one-time passwords, password reset links, calendar <a class=\"wpil_keyword_link\" href=\"https:\/\/thecyberexpress.com\/cyber-security-events\/\" title=\"events\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"28717\" rel=\"nofollow noopener\" target=\"_blank\">events<\/a>, meeting notes, attendee information, confidential communications, SharePoint files, OneDrive documents, earnings reports, salary information, acquisition plans, and other sensitive business records.\u00a0<\/p>\n<p>The researchers noted that the novelty of the\u00a0SearchLeak\u00a0<a class=\"wpil_keyword_link\" href=\"https:\/\/thecyberexpress.com\/firewall-daily\/vulnerabilities\/\" title=\"vulnerability\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"28720\" rel=\"nofollow noopener\" target=\"_blank\">vulnerability<\/a> lies in how AI-enabled prompt injection made older attack techniques practical in\u00a0a new environment. Without the P2P flaw, attackers could not inject malicious instructions; without the race condition, the HTML would be neutralized; and without the SSRF weakness, the Content Security Policy would block data exfiltration.\u00a0<\/p>\n<p>Microsoft has since remediated the issue under\u00a0CVE-2026-42824, but researchers say the case highlights how AI systems can introduce new attack paths by connecting previously understood <a class=\"wpil_keyword_link\" href=\"https:\/\/thecyberexpress.com\/what-are-vulnerabilities\/\" title=\"vulnerabilities\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"28718\" rel=\"nofollow noopener\" target=\"_blank\">vulnerabilities<\/a> in unexpected ways.\u00a0<\/p>\n<p>\n\tRelated<\/p>\n","protected":false},"excerpt":{"rendered":"A newly disclosed\u00a0SearchLeak\u00a0vulnerability\u00a0in\u00a0Microsoft 365 Copilot Enterprise\u00a0exposed a critical pathway for attackers to steal sensitive organizational data through a&hellip;\n","protected":false},"author":2,"featured_media":75243,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7853,416,41361,320,41362,7852,41363,11188,25782,25783],"class_list":["post-75242","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-copilot","tag-copilot","tag-cve-2026-42824","tag-microsoft","tag-microsoft-365-copilot-enterprise","tag-microsoft-copilot","tag-searchleak-vulnerability","tag-sharepoint","tag-the-cyber-express","tag-the-cyber-express-news"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/75242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=75242"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/75242\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/75243"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=75242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=75242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=75242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}