Microsoft patched a critical flaw in Microsoft 365 Copilot Enterprise that could let an attacker steal sensitive data from a user's email, OneDrive, SharePoint, and calendar after the user clicked a crafted link. The issue, CVE-2026-42824, was demonstrated as a three-part attack chain dubbed SearchLeak that combined parameter-to-prompt injection, an HTML rendering race condition, and a Bing server-side request forgery (SSRF) path to bypass content security protections and exfiltrate Copilot search results.
Why it matters: Organizations using Microsoft 365 Copilot Enterprise could have had internal data quietly siphoned out through normal-looking links, with little visible sign to the victim. The fix is already available, so defenders should verify Microsoft 365 Copilot protections are current and review for suspicious link-based abuse involving Copilot, Bing, OneDrive, SharePoint, and Exchange data.
info@thehackernews.com (The Hacker News)
2026.06.15
99% relevant
The article appears to cover the same underlying event: Microsoft's fix for CVE-2026-42824 in Microsoft 365 Copilot, described here as a one-click flaw that could expose emails, files, and one-time MFA codes.
Bill Toulas
2026.06.15
100% relevant
This article appears to be the initial report establishing a distinct tracked story around CVE-2026-42824 and the SearchLeak attack chain in Microsoft 365 Copilot Enterprise.
← Back to all stories