logo

How an Improper Access Control Vulnerability Led to Account Theft in One Click

ID: f4f5c1d2-4618-5d7b-8991-0a1887e7267e

STIX ID: report--f4f5c1d2-4618-5d7b-8991-0a1887e7267e

Feed Name: HackerOne Blog

Threat Score
75/100

Date Published: 2024-11-27

Date Updated: 2026-06-12

...
...

This HackerOne report explains improper access control risks, business impacts, and remediation guidance, and highlights a critical real-world example where a malicious deeplink in the KAYAK Android app allowed an unauthenticated attacker to steal session cookies and perform one-click account takeover; KAYAK issued a patch via Google Play the next day.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.