# SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data Exfiltration (CVE-2026-42824)

> SearchLeak is a one-click data-exfiltration vulnerability chain in Microsoft 365 Copilot Enterprise Search discovered by Varonis Threat Labs. It chains parameter-to-prompt injection via the 'q' URL parameter, an HTML rendering race condition during Copilot's response streaming that fires attacker <img> tags before sanitization wraps output in <code> blocks, and a Content-Security-Policy bypass via server-side request forgery (SSRF) through Bing's allowlisted 'Search by Image' endpoint to leak mailbox contents, MFA/one-time codes, calendar data, and SharePoint/OneDrive files. Microsoft assigned CVE-2026-42824, rated it Critical, and fully mitigated it server-side; only a proof-of-concept was demonstrated, with no observed in-the-wild exploitation.

- **Published:** 2026-06-15T00:00:00Z
- **Last reviewed:** 2026-06-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0806
- **ID:** TL-2026-0806
- **Severity:** CRITICAL (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-42824

## Description

SearchLeak (CVE-2026-42824) is a three-stage exploit chain against Microsoft 365 Copilot Enterprise Search demonstrated by Varonis Threat Labs researcher Dolev Taler. Individually the three bugs are insufficient for a meaningful attack; chained together they enable single-click theft of any data the victim's Copilot can reach through inherited Microsoft Graph access.

Stage 1 — Parameter-to-prompt injection: The Copilot Enterprise Search URL exposes a 'q' parameter intended for search terms. Copilot reads whatever sits in 'q' as instructions rather than a literal query, so an attacker crafts a link instructing Copilot to search the victim's mailbox (or other data sources), extract values such as email subjects or one-time codes, and embed them in an image URL — all without the victim typing anything. Because the crafted link points to a legitimate microsoft.com domain, traditional anti-phishing and URL-filtering tools are unlikely to flag it.

Stage 2 — HTML rendering race condition: As a guardrail, Microsoft wraps dangerous Copilot-generated HTML inside <code> blocks so markup is not interpreted. The wrapping, however, only happens after Copilot finishes generating, while the browser renders the response stream as it arrives. During this streaming window the raw HTML — including an attacker-injected <img> tag — is temporarily live in the DOM and the browser issues the image request before sanitization neutralizes it.

Stage 3 — CSP bypass via Bing SSRF: Copilot's Content-Security-Policy blocks direct attacker-controlled connections, but allowlists *.bing.com. Bing's 'Search by Image' feature accepts an image URL parameter and performs a server-side fetch of that URL. The attacker points this feature at their own server with the stolen data encoded in the URL. Because the outbound request originates from Bing's infrastructure rather than the browser, CSP never applies, and Bing acts as an unwitting exfiltration proxy. The attacker reads the stolen data from their own server logs.

The full flow: the victim clicks the crafted Copilot Search link; Copilot searches the victim's data; the streamed response embeds a value such as an email subject in a Bing image URL; the browser calls Bing during streaming; Bing fetches the attacker's URL carrying the stolen data. Exfiltratable data includes email content (including access codes and passwords), one-time/MFA codes enabling rapid account takeover, calendar events and meeting notes, and SharePoint/OneDrive files indexed by Copilot Enterprise Search.

SearchLeak belongs to a recurring AI-assistant bug class: Varonis' earlier Reprompt attack used the same one-click technique against Copilot Personal and held up against Enterprise Search despite its extra guardrails, and Aim Labs' 2025 EchoLeak (CVE-2025-32711) was a zero-click variant. As the researchers note, SSRF and sanitizer races are old bug classes — the prompt injection is the new part. Microsoft assigned CVE-2026-42824 with a Critical (maximum) severity rating, CVSS 6.5 by Microsoft and 7.5 by NVD, and fully mitigated the flaw server-side in early June 2026; because Copilot Enterprise is a managed service, tenant administrators cannot patch the components themselves and no customer action is required.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1204 User Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1111 Multi-Factor Authentication Interception
- T1552 Unsecured Credentials
- T1114 Email Collection
- T1213 Data from Information Repositories
- T1530 Data from Cloud Storage
- T1102 Web Service
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service

## Sources

- [Microsoft 365 Copilot One-Click Vulnerability (SearchLeak)](https://cybersecuritynews.com/microsoft-365-copilot-one-click-vulnerability/)
- [New attack turned Microsoft 365 Copilot into 1-click data theft tool](https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/)
- [One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes](https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html)
- [CVE-2026-42824 - M365 Copilot Information Disclosure Vulnerability (MSRC Security Update Guide)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824)
- [EchoLeak in Microsoft Copilot: What it Means for AI Security (CVE-2025-32711)](https://www.varonis.com/blog/echoleak)
- [Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data](https://www.varonis.com/blog/reprompt)
- [Microsoft 365 Copilot Security Coverage](https://www.varonis.com/coverage/microsoft-365-copilot)
- [CVE-2026-42824 Information Disclosure Risk and AI Security Checklist](https://windowsnews.ai/article/cve-2026-42824-m365-copilot-info-disclosure-risk-and-ai-security-checklist.422843)
- [Microsoft fixes critical Copilot information disclosure vulnerabilities](https://letsdatascience.com/news/microsoft-fixes-critical-copilot-information-disclosure-vuln-b13fdf44)
- [CVE-2026-47644: Copilot Chat Information Disclosure Vulnerability Hits Microsoft Edge](https://windowsnews.ai/article/cve-2026-47644-copilot-chat-information-disclosure-vulnerability-hits-microsoft-edge.422849)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0806
