The Ultimate Guide to Non-Human Identities Report
NHI Forum

Notifications
Clear all

OneDrive File Picker Flaw Provides ChatGPT and Other Web Apps Full Read Access to Users’ Entire OneDrive


(@martaoasis)
Active Member
Joined: 4 weeks ago
Posts: 2
Topic starter  

Oasis Security's research team uncovered a flaw in Microsoft's OneDrive File Picker that allows websites to access a user’s entire OneDrive content, rather than just the specific files selected for upload via OneDrive File Picker. Researchers estimate that hundreds of apps are affected, including ChatGPT, Slack, Trello, and ClickUp–meaning millions of users may have already granted these apps access to their OneDrive. This flaw could have severe consequences, including customer data leakage and violation of compliance regulations.

Upon discovery, Oasis reported the flaw to Microsoft and advised vendors using OneDrive File Picker of the issue. In response, Microsoft is considering future improvements, including more precise alignment between what OneDrive File Picker does and the access it requires. 

Below are details of the flaw and mitigation strategies. You can read the Oasis Security Research team’s full report here.


   
Mr NHI reacted
Quote
Share: