logo

That Facebook Account Hijack Vulnerability Is Still Dangerous. Here’s Why.

ID: ca098895-a795-527c-8f9c-f0a8fd4c2304

STIX ID: report--ca098895-a795-527c-8f9c-f0a8fd4c2304

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2013-04-06

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The article describes the "UnFix Bug," a design flaw in Facebook's OAuth implementation identified by researcher Nir Goldshlager that can be exploited—via the redirect_uri parameter and site redirection vulnerabilities on third-party application publisher domains—to siphon Facebook access_tokens and hijack accounts; while some vendors patched specific redirects, many applications and subdomains (e.g., Zynga) may still be vulnerable, and exploitation requires an installed app with sufficient permissions and a redirect flaw on the publisher's website.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.