Researchers at Oasis Security say the problem has to do with OneDrive File Picker having overly broad permissions.