Back to Feed
VulnerabilitiesJun 15, 2026

Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

Copilot 'SearchLeak' attack allowed 1-click data theft via prompt injection.

Vendor Watch

Run Microsoft?

Get an email when a reviewed story names Microsoft, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy

Summary

A critical vulnerability dubbed 'SearchLeak' in Microsoft Copilot has been patched, which allowed attackers to steal data with a single click. The attack exploited prompt injection techniques, leveraging hidden URLs and other variables to trick the AI into revealing sensitive information. This incident highlights a growing class of vulnerabilities targeting AI systems.

Entities

Copilot (product)Microsoft (vendor)AI prompt-injection (technology)