Critical Copilot vulnerability allowed hackers to steal 2FA code from users
Summary
Researchers demonstrated a Copilot exploit dubbed SearchLeak that could pull sensitive data out of a user’s environment, including one time 2FA codes, by abusing how the assistant retrieves and reasons over search and contextual sources. The issue underscores how prompt and retrieval pathways can bypass normal isolation boundaries and expose secrets without traditional malware on the endpoint.
Why it matters
If assistants can leak 2FA codes through normal workflows, LLM deployments become a direct account takeover surface, not just a compliance and accuracy problem.