Microsoft 365 Copilot can be turned into a data theft tool with one click – Inbox, OneDrive and SharePoint data are all at risk, so patch now


  • Varonis exposed “SearchLeak” that chained three flaws in Microsoft 365 Copilot to enable one-click data theft
  • Attack leveraged prompt injection, HTML race mode and Bing SSRF to exfiltrate inbox, OneDrive and SharePoint data
  • Microsoft patched CVE-2026-42824 earlier this month and rated it 10/10 critical

Experts have revealed a way to turn Microsoft 365 Copilot into a one-click data theft tool capable of exfiltrating sensitive information from people’s inboxes, OneDrive and SharePoint instances.

The method was recently patched by Microsoft after being developed by security researchers Varonis, who dubbed the method SearchLeak and explained that it works by chaining together three vulnerabilities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top