SearchLeak is a better June story than another AI-security acquisition because it shows the architecture failing in public. The reported chain against Microsoft 365 Copilot was not just "prompt injection." It was prompt injection plus enterprise search plus an HTML rendering race plus a CSP bypass through Bing server-side request forgery. The model did not need admin rights. It only needed the user's normal access to email, OneDrive, SharePoint, and calendar data.

That is the Copilot risk model in miniature. Enterprise AI search is valuable because it can reach across the knowledge surface a user can reach. The same property makes it dangerous. If the assistant can retrieve everything the user is allowed to see, then every overshared SharePoint folder, stale Teams file, and permissive OneDrive link becomes part of the assistant's reachable context. SearchLeak adds the missing piece: a path from reachable context to outbound exfiltration.

The details matter because they are old bugs in a new arrangement. A malicious Copilot Enterprise Search URL carried instructions in a query parameter. Copilot treated the parameter as natural-language work. The generated response embedded retrieved data into an image URL. The browser rendered attacker-controlled HTML before sanitization completed. Bing's image search path then acted as the outbound fetcher, bypassing the content security policy that should have kept data inside the Microsoft boundary.

This is why "Copilot respects existing permissions" is necessary but not sufficient. Existing permissions are usually the problem. Enterprise tenants have years of inherited group grants, external sharing, stale project sites, and files that are technically authorized but operationally forgotten. A search assistant does not create that sprawl. It makes the sprawl queryable, summarizable, and, under the wrong chain, movable.

The useful response is not panic about one patched vulnerability. It is to treat enterprise AI search as a data-loss-prevention boundary:

  • Clean up overshared Microsoft 365 content before broad Copilot rollout.
  • Monitor Copilot/search prompts that ask for credentials, MFA codes, HR records, customer exports, and financial data.
  • Treat CSP allowlists as capability grants. If an allowed domain can fetch attacker-controlled URLs, it is not just an allowed domain.
  • Test prompt-injection chains that cross products: search, render, image fetch, email, Teams, browser, and proxy behavior.
  • Keep least privilege boring. Copilot inherits what the user can reach, so stale access becomes AI-readable access.

SearchLeak will be remembered as a Copilot bug because Copilot was the branded surface. The broader lesson is more durable: enterprise AI collapses data governance, browser security, and egress control into one path. If those controls are owned by different teams and tested separately, the exploit chain will find the join.

See also

References

  1. Microsoft 365 Copilot can be turned into a one-click data theft tool, TechRadar, 2026-06-16.
  2. A "critical" Microsoft Copilot exploit exposes AI gullibility, Windows Central, 2026-06-17.
  3. EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System, Pavan Reddy and Aditya Sanjay Gujral, 2025.