Blog | G5 Cyber Security

Facebook said to fix OAuth-based account hijacking flaw

Facebook has patched a serious vulnerability that could have allowed attackers to gain access to user account data. The vulnerability would have allowed a potential attacker to steal sensitive pieces of information known as OAuth access tokens. Facebook runs a bug bounty program through which it pays monetary rewards to security researchers who find and responsibly report vulnerabilities affecting the site. The researcher claims to have found a vulnerability on Facebook’s websites for mobile and touch-enabled devices that stemmed from improper sanitization of URL paths. Facebook has no evidence that users were affected by this bug.”]

Source: https://www.csoonline.com/article/2133023/privacy-facebook-said-to-fix-oauth-based-account-hijacking-flaw.html

Exit mobile version