vulns.co
/
GKData.io MCP

Varonis Threat Labs · 2 min read

SearchLeak: streamed output needs policy enforcement before browser activation

SearchLeak (CVE-2026-42824) illustrates a timing gap between streamed AI output becoming active in a browser and final-response sanitization. Varonis reports email-subject disclosure in a larger chain containing this failure. Cleaning the completed response cannot reverse effects that already occurred.

Open the reference Research PaperReviewed 2026-10-04

How to use this reference

Define output-safety invariants for every observable intermediate state, not just the completed answer. Keep generated content inert until applicable policy checks have passed. Review rendering and data-disclosure boundaries together; a clean final display is insufficient evidence that no earlier side effect occurred.

Before reading

  • Browser rendering, sanitization and content-security-policy concepts
  • AI output trust boundaries and ordering of security checks

Context and limits

  • The reported conditions require affected enterprise search, relevant content accessible to the victim and the victim opening a supplied link. This resource isolates the timing boundary; disclosure also depended on additional weaknesses.
  • Wider indexed-content exposure depends on the victim's access. Account takeover is a proposed consequence, not a demonstrated result in this record.
  • Varonis says Microsoft patched the issue. The exact fix date and implementation are not established by the reviewed evidence.
  • The Microsoft CNA record corroborates network information disclosure requiring user interaction and identifies an exclusively hosted service. It supplies no usable affected-version range. Its CWE-77 classification does not establish operating-system command execution.
  • The CNA's June 4, 2026 public-disclosure date and September 24 update date describe the vulnerability record, not this article's publication or remediation chronology.
  • No individual award amount or affected-victim count is established. This educational record grants no testing authorization.

Sources and provenance

  1. SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Varonis Threat Labs · reviewed 2026-10-04
  2. Varonis Blog catalog: SearchLeak entry Varonis · reviewed 2026-10-04
  3. Microsoft CNA record for CVE-2026-42824 Microsoft via CVE Program · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software