M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Varonis Threat Labs disclosed a proof-of-concept attack called SearchLeak targeting Microsoft 365 Copilot Enterprise Search. The attack chains three weaknesses: a parameter-to-prompt (P2P) injection via the URL's ?q= parameter, a race condition that allows HTML rendering during the model's thinking phase before output sanitization kicks in, and a CSP bypass using Bing Image Search as a proxy to exfiltrate data to an attacker-controlled server. The result is that a single crafted link clicked by a victim can leak sensitive corporate data — including emails, SharePoint documents, and even 2FA codes — without any authentication on the attacker's side. Microsoft patched the critical vulnerability server-side. The post also highlights P2P injection as a broader emerging attack class affecting other AI-powered web services, and offers mitigation guidance for developers and security teams.

6m read timeFrom csoonline.com
Post cover image
212 Impressions