oauth-callback

1 article
sort: new top best
clear filter
0 8/10

Authentication bypass on Airbnb via chained OAuth vulnerabilities: an HTTP Referer-based open redirect in the OAuth callback endpoint combined with login CSRF allowed attackers to steal OAuth access tokens from identity providers (Facebook/Google) and authenticate as victims on both web and mobile applications. The attack exploited Airbnb's use of long-term identity provider access tokens for mobile app authentication combined with weak referer-based redirect logic.

Airbnb Facebook Google Arne Swinnen Frans Rosén
arneswinnen.net · devanshbatham/Awesome-Bugbounty-Writeups · 6 hours ago · details