threat-intel
New attack turned Microsoft 365 Copilot into 1-click data theft tool
Critical
Summary
A critical vulnerability, dubbed SearchLeak, has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data from user mailboxes, OneDrive, and SharePoint accounts via a specially crafted URL. The attack chain exploits prompt injection, HTML rendering race conditions, and a Bing SSRF bypass, enabling data exfiltration without user interaction after Microsoft's patch. This highlights the potential for AI-powered systems to amplify the impact of traditional vulnerabilities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data