Writer AI Vulnerability May Have Leaked Across Tenants via Live Preview

Colleagues, I’d like to draw your attention to a cybersecurity and AI incident.
Writer AI identified a critical session-isolation flaw. Through live preview, an attacker could potentially intercept a user’s session token from another company.
A user opens a link, the browser sends cookies, and the sandbox gains access to the token and account data.
This could expose chats, documents, and settings, and in some cases admin functions.
The issue has now been fixed: cookies are no longer passed to sandbox previews, and previews have been moved to an isolated origin.
Why it matters: AI features require strict isolation and robust tenant separation controls.
Are you reviewing your policies for preview links and sandbox environments?
#cybersecurity #AI #vulnerability #infosec

