Microsoft fixed critical Microsoft 365 Copilot flaw CVE-2026-42824 that let one click steal mailbox and SharePoint data

Microsoft patched a critical flaw in Microsoft 365 Copilot Enterprise that could let an attacker steal sensitive data from a user's email, OneDrive, SharePoint, and calendar after the user clicked a crafted link. The issue, CVE-2026-42824, was demonstrated as a three-part attack chain dubbed SearchLeak that combined parameter-to-prompt injection, an HTML rendering race condition, and a Bing server-side request forgery (SSRF) path to bypass content security protections and exfiltrate Copilot search results.
Why it matters: Organizations using Microsoft 365 Copilot Enterprise could have had internal data quietly siphoned out through normal-looking links, with little visible sign to the victim. The fix is already available, so defenders should verify Microsoft 365 Copilot protections are current and review for suspicious link-based abuse involving Copilot, Bing, OneDrive, SharePoint, and Exchange data.

Sources

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
info@thehackernews.com (The Hacker News) 2026.06.15 99% relevant
The article appears to cover the same underlying event: Microsoft's fix for CVE-2026-42824 in Microsoft 365 Copilot, described here as a one-click flaw that could expose emails, files, and one-time MFA codes.
New attack turned Microsoft 365 Copilot into 1-click data theft tool
Bill Toulas 2026.06.15 100% relevant
This article appears to be the initial report establishing a distinct tracked story around CVE-2026-42824 and the SearchLeak attack chain in Microsoft 365 Copilot Enterprise.
← Back to all stories