logo

OAuth Flaw Exposed Millions of Airline Users to Account Takeovers

ID: 81814e33-aae6-53d3-a82d-979fc68f1747

STIX ID: report--81814e33-aae6-53d3-a82d-979fc68f1747

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2025-01-28

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers at Salt Security discovered a critical OAuth implementation flaw in a major travel services provider that could redirect users' authorization credentials to attacker-controlled servers, enabling full account takeover of airline-linked accounts and access to personal and rewards data; the vendor has since fixed the issue. The report emphasizes the systemic risk of insecure third-party integrations, cites prior similar findings (e.g., Booking.com, Grammarly), and notes that attacks would appear indistinguishable from legitimate requests to affected airlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.