What’s alarming here is that Microsoft also rated the vulnerability as ‘max severity: critical,’ and has also fixed at, as stated by Varonis. The company explained, ‘To exfiltrate the data, an attacker crafts a URL that tells Copilot to ‘Search the user’s emails, extract the title, and embed it in an image URL. The victim doesn’t type anything. They click a link, and Copilot does the rest.’
Critical Copilot Bug Exposed Emails, Files, And MFA Codes To Hackers
- Post author:loknad
- Post published:June 19, 2026
- Post category:Uncategorized
- Post comments:0 Comments