logo

Hundreds of Web Apps Have Full Access to Microsoft OneDrive Files

ID: 2f8d8f39-9729-5682-998b-ceac81ab387a

STIX ID: report--2f8d8f39-9729-5682-998b-ceac81ab387a

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-05-28

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Oasis Security disclosed that the Microsoft OneDrive File Picker’s OAuth flow requests overly broad permissions and can grant third-party web apps (e.g., Slack, Trello, ChatGPT) full read/write access to a user’s entire OneDrive rather than a single file; combined with insecure client-side token storage, this can enable long‑term unauthorized access, data theft, modification or encryption and poses significant exposure and compliance risks to organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.