Microsoft 365 Copilot can become a one-click data theft tool: Inbox, OneDrive, and SharePoint data is at risk, so patch now



  • Varonis discovered “SearchLeak”, chaining three flaws in Microsoft 365 Copilot to allow data theft with a single click
  • The attack leveraged fast injection, HTML race condition, and Bing SSRF to leak data from Inbox, OneDrive, and SharePoint.
  • Microsoft patched CVE-2026-42824 earlier this month, rating it a critical 10/10

Experts have discovered a way to turn Microsoft 365 Copilot into a one-click data theft tool, capable of extracting sensitive information from people’s inboxes, OneDrive and SharePoint instances.

The method was recently patched by Microsoft and was developed by security researchers Varonis, who called it SearchLeak and explained that it works by chaining three vulnerabilities.

Leave a Comment

Your email address will not be published. Required fields are marked *