Threat · curated 27 Jun 2026
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
First reported darkreading.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
It demonstrates how prompt injection with hidden URLs can exfiltrate data from AI assistants like Copilot, a direct risk to enterprise users.
A three-stage 'SearchLeak' attack against Copilot enabled 1-click data theft using hidden URLs and other variables, part of a new class of AI prompt-injection issues. The vulnerability has now been patched.