logo

OAuth+XSS Attack Threatens Millions of Web Users With Account Takeover

ID: 5cad5eb0-ba4e-594c-b316-0a73ad60e45c

STIX ID: report--5cad5eb0-ba4e-594c-b316-0a73ad60e45c

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-07-29

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Salt Labs identified a critical attack chain that pairs OAuth implementation flaws with cross-site scripting (XSS) to steal authentication tokens and perform account takeover. The research demonstrated this against Hotjar (a service used by over one million sites) and Business Insider, highlighting the potential exposure of names, emails, messages, bank details, and credentials; both issues were reported and remediated, but researchers warn the combination is likely widespread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.