Hundreds of Web Apps Have Full Access to Microsoft OneDrive Files
ID: 2f8d8f39-9729-5682-998b-ceac81ab387a
STIX ID: report--2f8d8f39-9729-5682-998b-ceac81ab387a
Feed Name: Dark Reading
Threat Score
Oasis Security disclosed that the Microsoft OneDrive File Picker’s OAuth flow requests overly broad permissions and can grant third-party web apps (e.g., Slack, Trello, ChatGPT) full read/write access to a user’s entire OneDrive rather than a single file; combined with insecure client-side token storage, this can enable long‑term unauthorized access, data theft, modification or encryption and poses significant exposure and compliance risks to organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
