YOU ARE VIEWING ONE ITEM FROM THE AICRIER FEED

SearchLeak exposes Microsoft 365 Copilot data

AICrier tracks AI developer news across Product Hunt, GitHub, Hacker News, YouTube, X, arXiv, and more. This page keeps the article you opened front and center while giving you a path into the live feed.

// WHAT AICRIER DOES

7+

TRACKED FEEDS

24/7

SCRAPED FEED

Short summaries, external links, screenshots, relevance scoring, tags, and featured picks for AI builders.

SearchLeak exposes Microsoft 365 Copilot data
OPEN LINK ↗
// 2h agoSECURITY INCIDENT

SearchLeak exposes Microsoft 365 Copilot data

Varonis Threat Labs discovered 'SearchLeak,' a critical one-click vulnerability chain in Microsoft 365 Copilot tracked under CVE-2026-42824. The exploit chains a Parameter-to-Prompt injection with a browser rendering race condition and a Bing SSRF bypass to silently exfiltrate organizational data.

// ANALYSIS

Combining LLMs with direct graph access and untrusted URL inputs creates an inherently insecure attack surface that elevates classic web bugs into critical enterprise-wide compromise vectors.

* Parameter-to-Prompt (P2P) injection turns a natural language search query parameter into a silent, auto-executed instruction set.

* Incremental DOM rendering during streaming allows malicious HTML image tags to execute and fire HTTP requests before Copilot's post-processing output sanitizer wraps the response.

* Allowed CSP domains like Bing can be abused as exfiltration proxies by triggering their server-side request forgery (SSRF) endpoints.

* Since Copilot inherits the victim's full graph permissions, attackers can silently access MFA codes, emails, calendars, and private company files with zero additional verification.

// TAGS
securityvulnerabilitymicrosoft-365-copilotvaronisssrfcsp-bypassdata-exfiltration

DISCOVERED

2h ago

2026-06-15

PUBLISHED

3h ago

2026-06-15

RELEVANCE

9/ 10

AUTHOR

IntCyberDigest