Tech

A key Microsoft OneDrive feature has a worrying security flaw which could expose user data

Share
Share


  • Researchers found a flaw in Microsoft OneDrive File Picker
  • The flaw stems in the lack of fine-grained OAuth permissions
  • Microsoft acknowledges the flaw, but hasn’t fixed it yet

A vulnerability in Microsoft’s OneDrive File Picker has been found which could allow threat actors to access people’s entire cloud archives, experts have warned.

Security researchers Oasis discovered the flaw and reported it to Microsoft, noting the problem lies in excessive permissions that File Picker asks for – including read access to the entire drive. The tool asks for these permissions since the OAuth scopes for OneDrive aren’t fine-grained.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Exploring the real reasons why some people choose not to use AI
Tech

Exploring the real reasons why some people choose not to use AI

Credit: CC0 Public Domain Generative artificial intelligence is everywhere, but not everyone...

New method enables sustainable recycling of rare earths from electrolyzers
Tech

New method enables sustainable recycling of rare earths from electrolyzers

Credit: Journal of Sustainable Metallurgy (2025). DOI: 10.1007/s40831-025-01080-9 Hydrogen electrolysis cells contain...