Threat · curated 27 Jun 2026

Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

Coverage timeline

15 Jun 2026darkreading.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

It demonstrates how prompt injection with hidden URLs can exfiltrate data from AI assistants like Copilot, a direct risk to enterprise users.

A three-stage 'SearchLeak' attack against Copilot enabled 1-click data theft using hidden URLs and other variables, part of a new class of AI prompt-injection issues. The vulnerability has now been patched.