Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A critical vulnerability, SearchLeak (CVE-2026-42824), in Microsoft 365 Copilot Enterprise allowed attackers to exploit AI prompt injection and web security flaws to steal sensitive data, including emails and authentication codes, via crafted URLs. Discovered by Varonis, the flaw was patched by Microsoft, but exposed significant AI-driven data security risks.[AI generated]

Why's our monitor labelling this an incident or hazard?

Microsoft 365 Copilot is an AI system that processes user inputs to generate responses and perform searches across user data. The described attack exploited AI-specific vulnerabilities (prompt injection) and other security flaws to steal sensitive data, directly causing harm through unauthorized data exfiltration. The incident involves the AI system's use and malfunction leading to a breach of privacy and security, which fits the definition of an AI Incident under violations of rights and harm to property or communities. The fact that the vulnerability was patched after being exploited confirms the harm was realized, not just potential.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
BusinessWorkers

Harm types
Human or fundamental rights

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard