Microsoft 365 Copilot can be turned into a data theft tool in one click: Inbox data, OneDrive and SharePoint are all at risk, so patch now


  • Varonis discovered “SearchLeak,” chaining three vulnerabilities in Microsoft 365 Copilot to enable data theft in one click
  • The attack leveraged rapid injection, HTML race condition, and Bing SSRF to exfiltrate data from Inbox, OneDrive, and SharePoint.
  • Microsoft patched CVE‑2026‑42824 earlier this month, giving it a critical rating of 10/10.

Experts have discovered a way to turn Microsoft 365 Copilot into a one-click data theft tool capable of exfiltrating sensitive information from users’ inboxes, OneDrive, and SharePoint instances.

The method was recently patched by Microsoft after being developed by security researchers Varonis, who dubbed the method SearchLeak, explaining that it works by chaining three vulnerabilities together.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top