SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Reading: If you use OneDrive to upload files to ChatGPT or Zoom, don’t
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > AI > If you use OneDrive to upload files to ChatGPT or Zoom, don’t
AI

If you use OneDrive to upload files to ChatGPT or Zoom, don’t

News Room
Last updated: May 28, 2025 2:33 pm
News Room
Share
1 Min Read
SHARE

OneDrive File Picker is a Microsoft-provided tool that lets websites and web apps integrate with a user’s OneDrive account to allow uploading, browsing, and selecting OneDrive files directly from the app.

An over-privileged OAuth trap

This broad access stems from a limitation in Microsoft’s OAuth implementation within File Picker that researchers described as “a lack of fine-grained permissions scopes.”

Jason Soroko, senior fellow at Sectigo, calls the oversight an over-privileged OAuth trap. “Microsoft’s OneDrive File Picker encourages third-party web apps to request broad files,” he said. “Once issued, those long-lived tokens are often cached in localStorage or back-end databases without any encryption, potentially allowing attackers to trawl an entire tenant’s data.”

OneDrive File Picker’s OAuth implementation requests broad scopes, instead of fine-grained, file-level scopes, allowing users and developers to restrict access to only the files explicitly selected.

Read the full article here

You Might Also Like

For June’s Patch Tuesday, 68 fixes — and two zero-day flaws

Microsoft OneNote cheat sheet – Computerworld

A landmark copyright fight over genAI – Computerworld

Open source AI hiring models are weighted toward male candidates, study finds – Computerworld

Models defy human commands, actively resist orders to shut down – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Games

Brace yourself: Hades 2 just got what ‘will likely be our final patch’ before full release

July 3, 2025
Games

MindsEye boss reportedly blames its failure on ‘saboteurs’ and says a re-launch is in the works, even as the entire development studio is at risk of layoff

July 3, 2025
Games

Marvel Rivals’ updated hero hot list reveals the most-played and highest win-rate characters, and it’s good news for Support players

July 3, 2025
News

Seattle leaders scrutinize $90M tax plan: Relief for small businesses, higher bills for big tech

July 3, 2025
Games

All active Anime Vanguards codes in July 2025 and how to redeem them

July 3, 2025
Games

Rematch’s developers expected players to develop new tech fast, but ‘not nearly as fast as it is going right now’

July 3, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?