Alleged Vulnerability in Microsoft 365 Copilot Enterprise
- 事件类型
- Vulnerability
- 报告时间
- 2026-06-15 22:05:22
- 被攻击国家/地区
- USA
- 被攻击行业
- Information Technology (IT) Services
- 被攻击组织
- microsoft
- 被攻击域名
- microsoft.com
- 攻击组织
- None
- 信息来源
- openweb
A critical vulnerability chain dubbed SearchLeak (CVE-2026-42824) was discovered in Microsoft 365 Copilot Enterprise, enabling potential one-click data theft via a malicious URL. The attack chained three flaws-prompt injection through the Copilot search parameter, an HTML rendering race condition, and an SSRF issue in Bing’s image search to extract sensitive data from emails, OneDrive, SharePoint, and calendar events. When a victim clicks a crafted link, Copilot is manipulated into retrieving internal data and embedding it in image requests that are silently sent to an attacker-controlled server via Bing. Microsoft has already patched the issue, and no user action is required, but it highlights how combining multiple vulnerabilities can turn AI systems into powerful data exfiltration tools.