That Facebook Account Hijack Vulnerability Is Still Dangerous. Here’s Why.
ID: ca098895-a795-527c-8f9c-f0a8fd4c2304
STIX ID: report--ca098895-a795-527c-8f9c-f0a8fd4c2304
Feed Name: Security Ledger
The article describes the "UnFix Bug," a design flaw in Facebook's OAuth implementation identified by researcher Nir Goldshlager that can be exploited—via the redirect_uri parameter and site redirection vulnerabilities on third-party application publisher domains—to siphon Facebook access_tokens and hijack accounts; while some vendors patched specific redirects, many applications and subdomains (e.g., Zynga) may still be vulnerable, and exploitation requires an installed app with sufficient permissions and a redirect flaw on the publisher's website.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
