Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
A critical vulnerability, dubbed ‘SearchLeak,’ has been discovered in Microsoft Copilot that allows attackers to silently steal user data through a novel prompt injection technique. The attack leverages a race condition involving Bing search-by-image to bypass Copilot’s guardrails and extract sensitive information like emails, meeting notes, and OneDrive files. While Microsoft has patched the vulnerability, experts warn that this represents a broader risk in LLM-powered enterprise assistants, highlighting the need for organizations to proactively manage prompt injection and data exposure.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
