VulnerabilitiesJun 15, 2026
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
Copilot 'SearchLeak' attack allowed 1-click data theft via prompt injection.
Vendor Watch
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
A critical vulnerability dubbed 'SearchLeak' in Microsoft Copilot has been patched, which allowed attackers to steal data with a single click. The attack exploited prompt injection techniques, leveraging hidden URLs and other variables to trick the AI into revealing sensitive information. This incident highlights a growing class of vulnerabilities targeting AI systems.
Entities
Copilot (product)Microsoft (vendor)AI prompt-injection (technology)