INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

One-Click Microsoft 365 Data Theft Vulnerability Exploit

| 2026-06-15 15:09 CRITICAL HIGH
Executive Summary AI-generated
The discovery of SearchLeak, a one-click exfiltration path exploited by three bugs in Microsoft's Copilot Enterprise Search tool, has significant implications for enterprise security. The technique leverages vulnerabilities in the software to steal sensitive information such as emails, files, and MFA codes. This could have far-reaching consequences, including unauthorized access to user accounts, intellectual property, and confidential data. As a result, organizations must take immediate action to patch these vulnerabilities and implement additional security measures to prevent exploitation of this technique.
Technical Mitigations AI-generated
* Implement Content Security Policy (CSP) blocking: Ensure that the Microsoft Graph API and SharePoint/OneDrive data is blocked by CSP, preventing attackers from accessing sensitive information. * Use a secure protocol for communication with Bing: When communicating with Bing to retrieve stolen data, use HTTPS or a secure tunneling protocol like TLS 1.2 to encrypt the communication between the attacker's server and the victim's browser. * Implement rate limiting on API calls: Limit the number of API calls made by an attacker within a certain time frame (e.g., 10-15 minutes) to prevent them from exploiting the vulnerability repeatedly. * Use a secure password manager or generate strong passwords: Ensure that all accounts, including Microsoft Graph and SharePoint/OneDrive, use strong, unique passwords or have a secure password manager in place to protect against data theft. * Monitor for suspicious activity and implement incident response plan: Establish an incident response plan to quickly respond to potential security incidents, such as unauthorized access to sensitive information.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42824CVE-2026-42824 CVE-2025-32711CVE-2025-32711
Target & Sectors
Global Scope
Incident Timeline
‎Jun 15, 2026
Attackers exploited a one-click exfiltration path by chaining three bugs into the Copilot Enterprise Search URL, allowing them to steal emails, files, and MFA codes.
organisation CVSS
organisation /Your_Security_Code_847291
organisation CVE-2025-32711
organisation Aim Security
organisation SearchLeak
organisation the Copilot Enterprise Search
organisation Copilot
organisation Next
organisation Content Security Policy
organisation CSP
organisation Copilot Enterprise
organisation Microsoft Graph
organisation MFA
organisation SharePoint
organisation OneDrive
organisation Copilot Personal
organisation HTML
‎2026/06/15
Attackers exploited a parameter-to-prompt (P2P) injection weakness in Microsoft 365 Copilot Enterprise Search to steal emails, files, and MFA codes by clicking on trusted links.
infrastructure Microsoft 365
organisation MFA Codes
organisation Vulnerability / Enterprise Security
organisation Microsoft
organisation Microsoft 365 Copilot Enterprise Search
organisation Microsoft 365 Copilot
organisation SharePoint
organisation OneDrive
organisation Microsoft 365 Copilot Enterprise
organisation Microsoft 365 Copilot Search
organisation SearchLeak
organisation Copilot
organisation Microsoft Copilot Enterprise Search
organisation Next
organisation CSP
organisation HTML
organisation Copilot Enterprise Search
organisation Bing’s “Search by Image
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product