All Topics
All Topics
Technology
Technology
AI
AI
Business
Business
Entertainment
Entertainment
News
News
Programming
Programming
Security
Security
Science
Science
Design
Design
Environment
Environment
Finance
Finance
Crypto
Crypto
Politics
Politics
Sports
Sports
Education
Education
Gaming
Gaming
Art
Art
Music
Music
Health
Health
Books
Books
Food
Food
Travel
Travel
Personal
Personal
Bluesky
Twitter

SearchLeak: Three-Bug Chain in Microsoft 365 Copilot Could Enable One-Click Data Exfiltration

19d ago· 1 min readenNews

Summary

Security researchers discovered a vulnerability chain called "SearchLeak" in Microsoft 365 Copilot Enterprise Search that could allow attackers to exfiltrate emails, calendar details, and indexed files with a single click. The attack exploits three bugs: a Parameter-to-Prompt injection via the q URL parameter that treats user input as instructions, a race condition in response rendering that bypasses sanitization, and a Content Security Policy bypass using m365.cloud.microsoft domain behavior to load images from external domains.

Source

bskySearchLeak: Three-Bug Chain in Microsoft 365 Copilot Could Enable One-Click Data Exfiltrationbriefly.co

Key quotes

· 5 pulled
SearchLeak chains three bugs to enable one-click exfiltration from Microsoft 365 Copilot Enterprise Search, pulling emails, calendar details, and indexed files.
The entry point is the q parameter in the Copilot Enterprise Search URL, which Copilot treats as instructions rather than a natural-language search string.
A Parameter-to-Prompt injection URL can instruct Copilot to search a mailbox, extract an email title, and embed it in an image URL.
A race condition in response rendering allows an injected tag to fire before browser wrapping and sanitization occur.
A final link bypasses the page's Content Security Policy by using m365.cloud.microsoft behavior to block images from an external domain.
Snippet from the RSS feed
SearchLeak chains three bugs to enable one-click exfiltration from Microsoft 365 Copilot Enterprise Search, pulling emails, calendar details, and indexed files. The entry point is the q parameter in the Copilot Enterprise Search URL, which Copilot treats

You might also wanna read

Comments

Sign in to join the conversation.

No comments yet. Be the first.