AIToday
Large Language ModelsAI Coding AssistantsArs Technica AIPublished: Jun 16, 2026, 22:00 JST1 min read

Microsoft patched critical vulnerabilities in Copilot that allowed attackers to steal two-factor authentication codes and other sensitive enterprise data through a technique called SearchLeak.

Microsoft patched critical vulnerabilities in Copilot that allowed attackers to steal two-factor authentication codes and other sensitive enterprise data through a technique called SearchLeak.

3 Key Points

  1. What happened

    Researchers discovered that attackers could send victims a specially crafted URL that caused Copilot to search the user's emails, extract information, and exfiltrate it to an attacker-controlled server. The attack exploited a timing gap in Copilot's safety guardrails—before protection mechanisms could wrap output in code blocks, the application generated raw HTML that included image tags, causing the user's browser to send HTTP requests containing stolen data. Bing search, which is whitelisted in Copilot's content security policy, was used as an intermediary to route the requests to the attacker's domain. Microsoft fixed the vulnerabilities on Tuesday.

  2. Why it matters

    The vulnerability targeted the Enterprise tier of Microsoft 365, meaning attackers could access not just personal data but anything an organization's user could see—emails, meeting invites, notes, SharePoint documents, OneDrive files, and other indexed business content. Depending on how M365 is configured, the blast radius could extend even wider across the environment. This demonstrates that even as Microsoft patches individual attack chains, researchers note there is no known way to fix the underlying cause of such vulnerabilities, suggesting similar exploits may emerge in the future.

  3. What to watch

    The researchers named the attack SearchLeak and published their findings on Monday. Because the attack relies on a fundamental gap between when Copilot streams output and when safety guardrails activate, the cat-and-mouse cycle between attackers finding new circumventions and Microsoft constructing new protections is likely to continue.

Ask the AI about this article →

Ars Technica AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Visko raises $10M, launches live AI video model OrbisSiliconANGLE AI · 2h ago
  • Runway unveils Solaris, an AI that generates app interfaces in real timeTHE DECODER · 2h ago
  • Google AI Search flags Facebook users as dangerTHE DECODER · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleSpaceX to acquire Cursor for $60 billion