windows-application

1 article
sort: new top best
clear filter
0 9/10

A chained CSRF vulnerability in Oculus-Facebook account linking allowed attackers to connect victims' Facebook accounts to attacker-controlled Oculus accounts, extract first-party Facebook access tokens via GraphQL queries, and achieve complete account takeover including password reset. The vulnerability required multiple fixes after initial attempts could be bypassed using a second CSRF on the Oculus login flow.

Josip Franjković Facebook Oculus graph.oculus.com graph.facebook.com auth.oculus.com
josipfranjkovic.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details