OAuth Flaw Exposed Millions of Airline Users to Account Takeovers
ID: 81814e33-aae6-53d3-a82d-979fc68f1747
STIX ID: report--81814e33-aae6-53d3-a82d-979fc68f1747
Feed Name: Dark Reading
Researchers at Salt Security discovered a critical OAuth implementation flaw in a major travel services provider that could redirect users' authorization credentials to attacker-controlled servers, enabling full account takeover of airline-linked accounts and access to personal and rewards data; the vendor has since fixed the issue. The report emphasizes the systemic risk of insecure third-party integrations, cites prior similar findings (e.g., Booking.com, Grammarly), and notes that attacks would appear indistinguishable from legitimate requests to affected airlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
