Critical Copilot Vulnerability Enabled Theft of 2FA Codes Through SearchLeak Exploit

A security flaw in Microsoft's Copilot allowed hackers to steal two-factor authentication codes, highlighting persistent LLM security challenges.

According to Ars Technica, a critical vulnerability in Microsoft’s Copilot allowed hackers to steal two-factor authentication codes from users through what researchers called the SearchLeak exploit. The vulnerability demonstrates recurring failures in the industry’s approach to securing large language models.

The SearchLeak exploit specifically targeted Copilot’s handling of user data, enabling attackers to extract sensitive authentication information that users had shared with the AI assistant. According to the report, this vulnerability represents a broader pattern of security failures across LLM implementations, where traditional security measures prove insufficient for protecting user information processed by AI systems.

The disclosure highlights ongoing challenges in securing AI assistants that handle sensitive user data. As these tools become more integrated into daily workflows and have access to personal information including authentication credentials, the industry faces mounting pressure to develop more robust security frameworks specifically designed for LLM-based applications rather than relying on conventional cybersecurity approaches that have repeatedly proven inadequate.