HackMyIP
← Back to News
2026-06-15 Dark Reading

Copilot SearchLeak Bug Enabled 1-Click Data Theft via Hidden URLs

AI SecurityAI ThreatsLLM Security

Microsoft has patched a critical vulnerability in its Copilot AI assistant that allowed attackers to steal sensitive user data—including emails, contact lists, and personal files—through a single click. Dubbed "SearchLeak" by researchers Michael Bargury and Tamir Shavrovsky of security firm Zenity, the flaw was disclosed at the recent Black Hat conference and represents a new class of AI prompt-injection attacks that weaponize hidden URLs and indirect prompt variables embedded in web content.

The attack unfolds in three distinct stages. First, an attacker poisons Copilot's search index by planting malicious instructions on public websites or shared documents. When a user later queries the AI assistant, Copilot ingests these hidden prompts and surfaces a crafted response containing an invisible hyperlink embedded in its output. The final stage triggers when the user clicks anywhere on the generated response—exfiltrating their session data, including authentication tokens and cached personal information, to the attacker's server. Because the malicious link is rendered through a legitimate Microsoft endpoint, traditional URL filtering and email security tools offered no defense. The technique builds on the same researcher's earlier "EchoLeak" zero-click exploit against Copilot, signaling a broader pattern of LLM-specific attack surfaces.

This disclosure highlights the rapidly evolving risk landscape around large language models, where natural-language interfaces bypass traditional security boundaries. Unlike conventional vulnerabilities, prompt injection exploits the semantic layer of AI systems, making them difficult to detect with signature-based defenses. Security teams should audit Copilot integrations for residual exposure, rotate any potentially compromised session tokens, and review access logs for anomalous outbound traffic to unfamiliar domains. Users concerned about credential exposure can verify whether their accounts appear in known incidents using a breach checker, while those evaluating their overall digital hygiene should run a comprehensive privacy checkup.

Although Microsoft assigned the report priority remediation and deployed a server-side patch, the underlying attack class remains a persistent concern across all major AI assistants. Organizations deploying Copilot, ChatGPT Enterprise, or similar tools should enforce strict data-loss-prevention policies, disable automatic web ingestion where possible, and require user confirmation before the assistant processes emails or documents containing sensitive content. As LLM-powered productivity tools become embedded in enterprise workflows, treating prompt-injection vectors with the same rigor as traditional infrastructure reconnaissance and supply-chain threats is no longer optional.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →