YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0065

Incident record

SearchLeak: one-click Microsoft 365 Copilot flaw could exfiltrate emails and codes

Severity
High
Status
Patched
Type
Prompt Injection
Target
Microsoft 365 Copilot
Actor
researcher
CVE
CVE-2026-42824

What happened

Varonis Threat Labs disclosed a chained one-click flaw it named SearchLeak in Microsoft 365 Copilot's enterprise search, combining a parameter-to-prompt-injection vector, a rendering race condition and an exfiltration path through trusted Microsoft domains. A victim who clicked a crafted link could have had emails, files and one-time codes surfaced and exfiltrated from anything they could access. Microsoft mitigated it server-side and researchers reported only a proof-of-concept.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026