The SearchLeak exploit allows attackers to bypass security layers and steal two-factor authentication codes from Microsoft Copilot users. This vulnerability highlights a persistent failure in how LLM-integrated tools handle sensitive data. Developers must now rethink how AI plugins interact with private user sessions to prevent similar credential theft across other AI assistants.