Other nomination
One Scheme to Rule Them All: OAuth Account Takeover
A malicious mobile app registers the custom URL scheme a legitimate app uses as its OAuth redirect_uri, so the authorization grant issued for that app's client_id is delivered to the attacker and the victim's account is taken over. Scheme conflicts are dodged by claiming the app's iOS scheme on Android or a loosely validated host, and consent is skipped via login_hint.
Record
- Researcher
- Mohamed Benchikh
- Published by
- Ostorlab
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mohamed Benchikh, first published at the original source. Preserved copies are kept so the citation survives its host.