Close Menu
GT NewsGT News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    India’s Modi to visit occupied Kashmir to unveil ‘strategic railway’

    June 4, 2025

    Hell is Us hits only 30 fps at 4K with an RTX 4090 and upscaling enabled

    June 4, 2025

    Massive planet discovered orbiting tiny star, leaving scientists stumped

    June 4, 2025
    Facebook X (Twitter) Instagram
    GT NewsGT News
    • Home
    • Trends
    • U.S
    • World
    • Business
    • Technology
    • Entertainment
    • Sports
    • Science
    • Health
    GT NewsGT News
    Home » OneDrive File Picker flaw grants full drive access when users share a single file
    Technology

    OneDrive File Picker flaw grants full drive access when users share a single file

    LuckyBy LuckyJune 2, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    OneDrive File Picker flaw grants full drive access when users share a single file
    Share
    Facebook Twitter LinkedIn Pinterest Email

    WTF?! OneDrive is one of the most popular cloud storage services in the market, largely because Microsoft aggressively promotes it to Windows users. However, security researchers warn that OneDrive’s File Picker feature may expose users and organizations to serious data risks by granting full read access to unauthorized parties.

    Microsoft is being extremely careless with security boundaries in OneDrive. A recent Oasis Security analysis revealed that OneDrive’s File Picker tool can grant websites, apps, and outside users full read-only access to all content stored on the service. This glaring flaw puts both individual users and corporations at risk, prompting Oasis to recommend a thorough audit of all previously granted permissions.

    File Picker provides companies and users with quick and easy file uploads from their OneDrive accounts. Many online services, including OpenAI’s ChatGPT, leverage this feature. However, rather than restricting access to a specific file, the tool grants external services blanket access to the entire storage space.

    Oasis estimates that hundreds of apps are affected by the issue, including ChatGPT, Slack, Trello, ClickUp, and others. As a result, millions of users have likely granted these services unrestricted access to their OneDrive files. This exposure could lead to data leaks and privacy violations, while organizations risk breaching regulatory compliance.

    Oasis also criticized Microsoft for using vague and misleading language when prompting users to initiate a file upload. It claims that Microsoft fails to disclose the full extent of access granted through File Picker, leaving customers unable to distinguish between legitimate requests and potentially malicious attempts to exfiltrate data.

    Oasis also warns that secret tokens used to grant access requests are often stored insecurely by default. In version 8.0 of File Picker, developers must implement authentication using Microsoft’s Authentication Library (MSAL) with OAuth’s Authorization Flow. However, the MSAL API stores tokens in the browser’s session storage in plain text, and the Authorization Flow can extend access indefinitely through a refresh token.

    “The lack of fine-grained OAuth scopes combined with Microsoft’s vague user prompt is a dangerous combination that puts both personal and enterprise users at risk,” Oasis said.

    As a result, individual users and enterprise administrators should review any third-party access permissions they have previously granted – a process Oasis outlines in a detailed checklist. The researchers have already reported the flaw to Microsoft and affected third-party vendors, and Redmond is reportedly considering future improvements to the service.

    access drive file flaw full grants OneDrive Picker Share single users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTwo space vets added to Astronaut Hall of Fame as one awaits launch
    Next Article Man who won $3.6 million lottery jackpot says girlfriend took the money and ‘ghosted’ him
    Lucky
    • Website

    Related Posts

    Technology

    Hell is Us hits only 30 fps at 4K with an RTX 4090 and upscaling enabled

    June 4, 2025
    Technology

    The EU Releases New Right to Repair Requirements for Phones and Tablets: What You Need to Know

    June 4, 2025
    Technology

    Scam calls evolve: Crocodilus malware adds fake contacts to Android phones

    June 4, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Stability trend for private markets to see in 2025

    February 21, 2025971 Views

    Appeals court allows Trump to enforce ban on DEI programs for now

    March 14, 2025943 Views

    My mom says these Sony headphones (down to $38) are the best gift I’ve given her

    February 21, 2025886 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    • Pinterest
    • Reddit
    • Telegram
    • Tumblr
    • Threads
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Stability trend for private markets to see in 2025

    February 21, 2025971 Views

    Appeals court allows Trump to enforce ban on DEI programs for now

    March 14, 2025943 Views

    My mom says these Sony headphones (down to $38) are the best gift I’ve given her

    February 21, 2025886 Views
    Our Picks

    India’s Modi to visit occupied Kashmir to unveil ‘strategic railway’

    June 4, 2025

    Hell is Us hits only 30 fps at 4K with an RTX 4090 and upscaling enabled

    June 4, 2025

    Massive planet discovered orbiting tiny star, leaving scientists stumped

    June 4, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest YouTube Tumblr Reddit Telegram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © .2025 gtnews.site Designed by Pro

    Type above and press Enter to search. Press Esc to cancel.