All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Microsoft Copilot vulnerability allowed data exfiltration via search function

Created at 16 Jun · 11:26 AM1 source↑ Market-relevant
IN SHORT

Researchers discovered a vulnerability in Microsoft Copilot, dubbed SearchLeak, that allowed attackers to exfiltrate sensitive user data, including emails and documents, by tricking the AI into embedding search queries within image URLs. Microsoft has since patched the vulnerability.

Key Numbers

2auth parameter in malicious URL

Who's Involved

Varonis
Security researchers who discovered and named the SearchLeak attack
Microsoft
Provider of the Copilot AI assistant and M365 Enterprise services
Microsoft Copilot vulnerability allowed data exfiltration via search function

↳ Why This Matters

This vulnerability highlights significant risks in AI assistants, demonstrating how sophisticated attacks can bypass security measures to exfiltrate sensitive enterprise data, potentially impacting a wide range of organizational information.

Key facts

  • A vulnerability in Microsoft Copilot, named SearchLeak, allowed attackers to exfiltrate user data.
  • Attackers crafted a URL that instructed Copilot to search user emails and embed the title in an image URL.
  • The exploit bypassed Copilot's output guardrails by leveraging the rendering of raw HTML before protection mechanisms engaged.
  • Microsoft's Bing search engine was used as a relay to send requests to attacker-controlled domains.
  • The vulnerability impacted the Enterprise tier of Microsoft 365, potentially exposing emails, meeting invites, documents, and other indexed content.
  • Microsoft has patched the vulnerabilities.

Researchers have identified a critical vulnerability in Microsoft Copilot, dubbed SearchLeak, that enabled attackers to exfiltrate sensitive user data. The attack exploits Copilot's search functionality by tricking users into clicking a specially crafted URL. This URL contains an instruction that prompts Copilot to search for specific information, such as a user's emails, and embed the title of the search result into an image URL.

The vulnerability arises because Copilot's output guardrails, which normally wrap responses in code blocks, activate only after the AI has finished processing. In the interim, Copilot generates its response using raw HTML, which is rendered in the browser's DOM. This allows an image tag within the response to be rendered and send an HTTP request to a source URL before the guardrail is applied.

To bypass limitations on sending image requests to arbitrary websites, attackers used Microsoft's Bing search engine as an intermediary. Bing is permitted by Copilot's content security policy to send such requests. Bing then forwards the request to an attacker-controlled domain specified in the original URL. This technique allowed attackers to extract data accessible to the targeted user within the Microsoft 365 Enterprise environment, including emails, meeting invites, SharePoint documents, and OneDrive files.

Microsoft confirmed the vulnerability and has since patched the exploited flaws.

Frequently asked questions

SearchLeak is a vulnerability in Microsoft Copilot that allowed attackers to exfiltrate sensitive user data by embedding search queries into image URLs, bypassing security guardrails.

Attackers sent users a malicious link that instructed Copilot to search for specific data (e.g., emails) and embed the result's title into an image URL, which was then relayed through Bing to an attacker-controlled server.

The attack could expose anything the user has access to within the organization, including emails, meeting invites, notes, SharePoint documents, and OneDrive files.

Yes, Microsoft patched the vulnerabilities that SearchLeak exploited on Tuesday.

What Happens Next

01Attackers may find new methods to circumvent newly constructed guardrails.
02Organizations should remain vigilant for further security threats targeting AI systems.

How It Developed

Researchers identified a vulnerability in Microsoft Copilot allowing attackers to exfiltrate data.
The attack, named SearchLeak, involved crafting a URL that instructed Copilot to search user emails and embed the title in an image URL.
Copilot's search functionality was exploited before its output guardrails could activate.
Attackers used Microsoft's Bing search engine as a relay to send requests to attacker-controlled domains.
The vulnerability affected the Enterprise tier of Microsoft 365, potentially exposing sensitive organizational data.
Microsoft patched the exploited vulnerabilities on Tuesday.

Sources

T1
Critical Copilot vulnerability allowed hackers to seal 2FA code from usersvar abtest_2159430 = new ABTest(2159430, 'impression');Ars Technica

Related Stories

Microsoft Copilot vulnerability allowed data exfiltration via URL prompts
18 Aug · 1:06 PM
OpenAI President Advocates AI Security Agents Post-Breach
17 Aug · 8:06 PM
Amazon confirmed trashing rare books for AI training
17 Aug · 6:21 PM
Zhipu AI's Project Glasswing rival signals shift in Chinese cybersecurity, researcher says
18 Aug · 3:05 AM
John Gruber criticizes Anthropic's AI watermarking as 'patently offensive'
17 Aug · 7:16 PM