#CVE-2026-42824
‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required.

CVE-2026-42824->critical.
June 15, 2026 at 10:46 PM
🧵CVE-2026-42824, o com es podíen filtrar els teus correus, calendari i documents compartits amb un sol enllaç.
Una URL ben construïda feia que Microsoft 365 Copilot Enterprise enviés dades de la teva empresa a un atacant. Sense que l'usuari insertes cap tipus de dada.
June 17, 2026 at 6:30 AM
The @varonis Threat Labs teams demonstrated that enterprise #AI assistants can be turned into a precision data exfiltration tool via a crafted link. #CVE-2026-42824 AKA #SearchLeak is a huge vulnerability chain in Microsoft 365 Copilot. HT HT @Kiteworks. cybersec.kiteworks.com/s/microsoft-...
Microsoft 365 Copilot SearchLeak (CVE-2026-42824): When Your AI Assistant Becomes an Exfiltration Tool
CVE-2026-42824 turns Microsoft 365 Copilot into a data exfiltration tool. Learn how the SearchLeak attack chain works and what defenders must do now.
cybersec.kiteworks.com
June 30, 2026 at 4:11 PM
Read this insight from Patrick Spencer of Kiteworks from June 23, 2026. "Microsoft 365 Copilot SearchLeak (CVE-2026-42824): When Your #AI Assistant Becomes an Exfiltration Tool" 🫨 cybersec.kiteworks.com/s/microsoft-...
July 20, 2026 at 1:31 PM
📰 Senjata Makan Tuan: Celah "SearchLeak" Ubah Microsoft 365 Copilot Menjadi Alat Pencuri Data Instan

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/15/celah-searchleak-copilot-microsoft-365-bocor/

#ai
#c#aid#cloudl#copilot2#cve42824 #hacke#hackera#keamananSibero#microsofto#microsoft
June 15, 2026 at 2:29 PM
For a year, 'prompt injection could exfiltrate your data' was a warning. Varonis made it a CVE. SearchLeak chained a prompt injection into Microsoft 365 Copilot with two web bugs: one click on a real microsoft.com link silently stole MFA codes, email, and files. Now patched.
A one-click Copilot flaw, SearchLeak, could steal MFA codes, email, and files
Varonis disclosed SearchLeak (CVE-2026-42824), a max-severity Microsoft 365 Copilot flaw chaining a prompt injection with two web bugs so one click on a real microsoft.com link silently exfiltrated MFA codes, email, and files. Patched server-side.
zubnet.ai
June 17, 2026 at 12:09 AM
Copilot EnterpriseのSearchLeakは正規リンク1クリックで社内メールを窃取
P2PインジェクションとBing SSRFの3段階連鎖、CVE-2026-42824は修正済み

#upppp
https://upppp.jp/app-service/20260616-160808/
upppp.jp
June 16, 2026 at 7:08 AM
Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click
Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click
A critical vulnerability chain in Microsoft 365 Copilot Enterprise that let attackers steal sensitive corporate data, MFA codes, email contents, calendar details, and confidential files with nothing more than a single click on a link pointing to a legitimate Microsoft domain. Dubbed SearchLeak, uncovered by Varonis Threat Labs and tracked as CVE-2026-42824 , the flaw earned Microsoft’s maximum severity rating before being patched. Its significance lies less in any single bug than in how it fuses a new AI-specific weakness with two well-worn web security flaws, turning Copilot Enterprise Search into a silent exfiltration channel. SearchLeak is not a single flaw; it is a chained exploit that weaponizes Microsoft 365 Copilot Enterprise Search as a silent data exfiltration engine. Detailed by Varonis researcher Dolev Taler, the attack combines three distinct weaknesses: a Parameter-to-Prompt (P2P) Injection, an HTML rendering race condition, and a Server-Side Request Forgery (SSRF) via Bing’s image search endpoint. Individually, each vulnerability is manageable. Chained together, they create a one-click attack capable of stealing virtually any data the victim can access within their Microsoft 365 tenant without requiring any special privileges, plugins, or secondary interactions. Microsoft 365 Copilot Vulnerability Chain Stage 1 — P2P Injection: Microsoft 365 Copilot Search accepts a q URL parameter intended for natural language search queries. The flaw is that whatever value is placed in the q parameter is interpreted by Copilot’s AI engine not just as a search string, but as executable instructions. An attacker crafts a malicious URL that points to a trusted microsoft.com domain and commands Copilot to search the victim’s mailbox and embed the extracted data in an image URL. Because the link resolves to a legitimate Microsoft domain, traditional anti-phishing and URL protection tools do not flag it. Stage 2 — Racing the Guardrail: Microsoft’s mitigation for dangerous AI-generated HTML is to wrap Copilot output in <code> blocks, preventing the browser from rendering it as markup. However, this wrapping only occurs after Copilot finishes its generation phase. During the streaming phase, raw HTML including attacker-injected <img> tags is temporarily rendered live in the DOM. The browser fires off the HTTP request before the sanitizer even activates, making this a textbook race condition bypass. Stage 3 — SSRF via Bing: The victim’s browser cannot directly contact an attacker-controlled server due to the Content Security Policy (CSP) on m365.cloud.microsoft . However, *.bing.com is CSP-allowlisted. Bing’s “Search by Image” feature accepts a imgurl parameter and performs a server-side fetch of the provided URL to analyze it. The attacker embeds the stolen data directly in the path of this Bing image-search URL. Bing’s backend unwittingly relays the stolen data to the attacker’s server, bypassing the CSP entirely. Microsoft 365 Copilot Attack Chain (Source: Varonis Threat Labs) The complete attack requires only a crafted link sent via email, Teams, Slack, or any messaging channel. When clicked, Copilot silently searches the victim’s mailbox, generates a response with embedded stolen data in a Bing image URL, and the attacker’s server logs the exfiltrated information all in seconds, with no second click. Defense Recommendations Microsoft has fully patched the SearchLeak server-side; no user action is required to receive the fix. However, Varonis recommends security teams: Monitor Copilot Search URLs for encoded payloads in the q parameter containing HTML or image-embedding instructions Audit CSP allowlists for any domain that performs server-side fetches on user-supplied URLs Treat AI streaming output as untrusted sanitization must occur at render time, not as a post-processing step Alert users to inspect Microsoft 365 links with long, encoded query strings before clicking SearchLeak follows Varonis’ earlier discovery of Reprompt , a similar one-click data exfiltration chain affecting Copilot Personal. Together, these findings underscore how AI assistants are creating new, hard-to-detect attack surfaces by reactivating previously unexploitable classic vulnerabilities in new contexts. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click appeared first on Cyber Security News .
cybersecuritynews.com
June 15, 2026 at 3:34 PM
A critical vulnerability in Microsoft 365 Copilot, tracked as CVE-2026-42824 and named SearchLeak, allows attackers to exfiltrate sensitive data with a single click.
Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click
cybersecuritynews.com
June 16, 2026 at 5:04 PM
🚨 EUVD-2026-42824
📊 6.9/10
🏢 Samsung Mobile

📝 Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42824

#cybersecurity #infosec #cve #euvd
July 10, 2026 at 6:00 AM
Un simple lien vers microsoft.com. Un clic. Et vos emails, vos codes MFA, vos documents SharePoint partent chez l'attaquant.

C'est SearchLeak (CVE-2026-42824),
👉 L'article complet : blog.gioria.org/fr/securite/...

#CyberSecurity #AISecurity #M365Copilot #PromptInjection #SSRF
July 8, 2026 at 7:01 AM
One-click SearchLeak in Microsoft 365 Copilot could expose emails, calendar details, files, and MFA codes via a trusted Microsoft link. Microsoft tagged it CVE-2026-42824 and mitigated it server-side. #SearchLeak #CVE2026 #Microsoft365
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Varonis Threat Labs uncovered SearchLeak, a one-click attack chain against Microsoft 365 Copilot Enterprise Search that could exfiltrate emails, calendar details, and indexed files through a trusted microsoft.com link. Microsoft assigned CVE-2026-42824 and mitigated the issue on the backend, while defenders are advised to monitor suspicious q-parameter payloads and unusual Bing...
www.hendryadrian.com
June 15, 2026 at 8:45 PM
SearchLeak turns Microsoft 365 Copilot Enterprise Search into a one-click exfiltration path via P2P injection, HTML race condition, and Bing SSRF. Microsoft patched CVE-2026-42824, rated critical. #SearchLeak #CVE202642824 #Microsoft365
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Varonis Threat Labs discovered SearchLeak, a three-stage attack chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration path by combining P2P injection, an HTML rendering race condition, and Bing-based SSRF. Microsoft patched the issue as CVE-2026-42824 with critical severity, and the chain could expose emails, security codes,...
www.hendryadrian.com
June 15, 2026 at 7:00 PM
Microsoft fixed CVE-2026-42824, where SearchLeak could turn Microsoft 365 Copilot Enterprise into a 1-click data theft tool, exposing emails, calendars, OneDrive, and SharePoint via a crafted URL. #SearchLeak #CVE202642824 #Microsoft365
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain called SearchLeak in Microsoft 365 Copilot Enterprise could let attackers steal sensitive data from mailboxes, OneDrive, and SharePoint through a specially crafted URL. Microsoft fixed the flaw as CVE-2026-42824, while researchers showed how prompt injection, an HTML rendering race condition, and a Bing SSRF issue could be chained to exfiltrate emails, calendar details, and documents. #Microsoft365CopilotEnterprise #SearchLeak #CVE-2026-42824 #Bing #Varonis
www.hendryadrian.com
June 15, 2026 at 4:00 PM
Microsoft Closes Major Copilot Flaw CVE-2026-42824 Amid AI Security Concerns
Microsoft Closes Major Copilot Flaw CVE-2026-42824 Amid AI Security Concerns
Microsoft patched the critical 'SearchLeak' vulnerability (CVE-2026-42824) in Copilot with server-side updates.
growmybag.tv
June 18, 2026 at 2:12 PM
Microsoft 365 Copilot SearchLeak (CVE-2026-42824): The One-Click AI Data Exfiltration Flaw That Exposes the Hidden Dangers of Over-Permissioned Data + Video

Introduction: The integration of Large Language Models (LLMs) into enterprise productivity suites has ushered in a new era of efficiency, but…
Microsoft 365 Copilot SearchLeak (CVE-2026-42824): The One-Click AI Data Exfiltration Flaw That Exposes the Hidden Dangers of Over-Permissioned Data + Video
Introduction: The integration of Large Language Models (LLMs) into enterprise productivity suites has ushered in a new era of efficiency, but it has also introduced a novel attack surface that traditional security controls are ill-equipped to handle. The recent disclosure of CVE-2026-42824, dubbed "SearchLeak," in Microsoft 365 Copilot Enterprise Search serves as a critical wake-up call for organizations worldwide. This vulnerability demonstrated that a single click on a seemingly legitimate Microsoft domain link could allow attackers to silently exfiltrate emails, calendar data, MFA codes, and indexed files without any further user interaction, exposing the fundamental truth that an AI is only as secure as the data it is permitted to access.
undercodetesting.com
June 16, 2026 at 3:17 PM
🟢 Critical Copilot bug allowed theft of two-factor authentication codes

🗨️ In early June, Microsoft engineers announced that they had fixed a critical vulnerability, CVE-2026-42824. Now specialis…

#news
Critical Copilot bug allowed theft of two-factor authentication codes
Read more
hackmag.com
June 18, 2026 at 6:30 PM
Microsoft 365 Copilot「SearchLeak」脆弱性、ワンクリックで情報窃取

https://www.yayafa.com/2824016/

2026年6月15日に公開された記事…
Microsoft 365 Copilot「SearchLeak」脆弱性、ワンクリックで情報窃取 - YAYAFA
2026年6月15日に公開された記事によると、Varonis Threat Labs がMicrosoft 365 Copilot Enterprise の脆弱性チェーン「SearchLeak」を発見したという。この脆弱性はCVE-2026-42824 として管理され、Microsoft
www.yayafa.com
June 16, 2026 at 11:40 PM
SearchLeak:Microsoft 365 Copilotのワンクリック脆弱性により機微なデータの窃取が可能に(CVE-2026-42824) | Codebook|Security News

https://www.yayafa.com/2823631/

SearchLeak:Microso…
SearchLeak:Microsoft 365 Copilotのワンクリック脆弱性により機微なデータの窃取が可能に(CVE-2026-42824) | Codebook|Security News - YAYAFA
SearchLeak:Microsoft 365 Copilotのワンクリック脆弱性により機微なデータの窃取が可能に(CVE-2026-42824)
www.yayafa.com
June 16, 2026 at 11:20 AM