threat-intel
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
High
Summary
A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The flaw exploited command injection and a race condition, leveraging Bing’s image endpoint to bypass security controls. While Microsoft has mitigated the issue on its backend, organizations need to monitor for suspicious activity and tighten data access governance.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
