Researcher Ori Lahav detailed the technical steps on LinkedIn: "The exploit chain involved: 🔓 Prompt Injection 🔓 Privilege Escalation 🔓 Path Traversal 🔓 .toml Injection 🔓 and finally an LD_PRELOAD Exploit" .
Microsoft patched the flaw by mid-March 2026 after Rubrik's responsible disclosure in February . Notably, Microsoft 365 Copilot customers did not need to deploy a new patch themselves since the fix was server-side
.
The ChatMate disclosure was part of a wave of related AI security findings at the same conference: