
Critical Session Isolation Flaw in Writer AI Platform Could Enable Cross-Tenant Compromise
CybersecurityVulnerabilitiesHackingAI_Security
Cybersecurity researchers disclosed a now-patched critical session isolation vulnerability in Writer, an enterprise generative AI platform, that could enable cross-tenant compromise. The flaw, codenamed WriteOut by the Sand Security Research team, was classified as a one-click vulnerability allowing unauthorized access escalation. An attacker with no prior access could exploit the issue to take over any Writer AI account. The vulnerability specifically involved session token leakage in agent previews, exposing sensitive authentication data across tenants. No CVE ID, specific dates, or affected version numbers were mentioned in the disclosure.