Tools AI Risk Radar ai-incident-0065
Incident record
SearchLeak: one-click Microsoft 365 Copilot flaw could exfiltrate emails and codes
- Severity
- High
- Status
- Patched
- Type
- Prompt Injection
- Target
- Microsoft 365 Copilot
- Actor
- researcher
- CVE
- CVE-2026-42824
What happened
Varonis Threat Labs disclosed a chained one-click flaw it named SearchLeak in Microsoft 365 Copilot's enterprise search, combining a parameter-to-prompt-injection vector, a rendering race condition and an exfiltration path through trusted Microsoft domains. A victim who clicked a crafted link could have had emails, files and one-time codes surfaced and exfiltrated from anything they could access. Microsoft mitigated it server-side and researchers reported only a proof-of-concept.
Sources
- Varonis Threat Labs: SearchLeak, how we turned M365 Copilot into a one-click data exfiltration weapon (15 June 2026)www.varonis.com/blog/searchleak
- Microsoft Security Response Center: the CVE-2026-42824 record (4 June 2026)api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026