The recent discovery of an XSS vulnerability in Bing.com has raised significant security concerns, potentially allowing attackers to send malicious requests to Microsoft's connected applications.
See also: Microsoft outage affects Bing, Copilot, DuckDuckGo, and ChatGPT

This vulnerability, which was discovered in Bing's main domain, highlights the risks associated with extensive web service integrations and underscores the potential for large‑scale exploitation.
The XSS vulnerability was uncovered during a detailed examination of Bing's API attack surfaces, focusing particularly on how the main Bing domain interacts with other Microsoft.
The research revealed that an XSS vulnerability could be used to execute arbitrary JavaScript on Bing's main domain, "www.bing.com."
The researcher, “pedbap,” observed that this execution could then be leveraged to create malicious requests targeting other Microsoft applications that users are signed in to by default, such as Outlook, Copilot , and OneDrive.
See also: iMessage & Microsoft Bing avoid EU tech crackdown
The attack starts by exploiting the XSS vulnerability to create a malicious link. This link allows attackers to execute JavaScript within the main domain of Bing.

Given Bing's integration with other Microsoft services, the malicious script can send requests that trigger sensitive actions on these platforms.
The widespread use of Bing amplifies the potential impact of the attack, as millions of users interact daily with Bing's features. Once executed, the malicious JavaScript could gain access to user data across many Microsoft services.
The discovery highlights significant security implications for both users and Microsoft. The ability to execute XSS attacks from a trusted domain like Bing is a serious threat, as it can lead to unauthorized access and manipulation of data.
See also: How to use Microsoft Copilot on iOS and iPadOS?
A cross-site scripting (XSS) vulnerability, such as the one in Bing, is a security flaw found in web applications that allows attackers to inject malicious scripts into content delivered to users. These scripts can be executed within a legitimate user session, potentially obtaining sensitive data such as cookies, session tokens, or other login details. XSS attacks generally occur when an application includes untrusted data in a web page that is sent to a user without proper validation. To prevent such vulnerabilities, developers should use strong input validation, escape, and content security policies to ensure that any malicious scripts are neutralized before rendering to the browser .
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
