Security News > 2016 > November > OAuth2.0 implementation flaw allows attackers to pop Android users’ accounts (Help Net Security)

OAuth2.0 implementation flaw allows attackers to pop Android users’ accounts (Help Net Security)
2016-11-08 21:03

Incorrect OAuth2.0 implementation by third party mobile app developers has opened users of those apps to account compromise, three researchers from the Chinese University of Hong Kong have discovered. The exploit The flaw can be exploited remotely, with no involvement and/or awareness of the victim. The attacker has to set up an ssl-enabled-MITM proxy for his device and a vulnerable third party app on his device. When he goes to sign into the mobile app … More →


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/uBf7eHwUsKE/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19