AI Briefing
KO

2FA Code Leak Vulnerability Discovered in Copilot

·2026.06.17 01:01

Key point

A vulnerability called 'SearchLeak', which leaks 2FA codes from Microsoft Copilot through prompt injection, has been reported.

Details

A vulnerability called 'SearchLeak' has been discovered in Microsoft Copilot that allows an attacker to steal a user's 2FA (two-factor authentication) code through a prompt injection attack.

This vulnerability exploits a security gap that occurs while the AI assistant processes user data, and its severity has been raised because it can neutralize 2FA, an otherwise strong security mechanism.

The key details are as follows:

  • Vulnerability name: SearchLeak
  • Attack method: Prompt Injection
  • Impact: Potential leakage of a user's two-factor authentication (2FA) code
  • Current status: Currently patched, but it highlights the risk of security threats that arise when LLM features are integrated

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.