API Bug in OAuth dev tool opened websites, apps to account hijacking
Critical flaw in the Expo framework that allowed them to take over user accounts via the Open Authorization (OAuth) protocol.
Source: scmagazine.com
Stay updated with breaking news from Open Authorization. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Critical flaw in the Expo framework that allowed them to take over user accounts via the Open Authorization (OAuth) protocol.
The vulnerability was discovered by Salt Security and has a CVSS score of 9.6
A cybersecurity vulnerability found in an implementation of the social login functionality opens the door to account takeovers and more.
How To Make Application' OAuth Device Authentication Flow Active? - Industry Tap
OAuth vulnerabilities on Booking.com could have resulted in account takeovers - SiliconANGLE