Critical API Security Vulnerabilities Found in OAuth Implementations of Popular Platforms

Salt Security’s recent research has uncovered critical API security vulnerabilities in the OAuth protocol implementations of widely used online platforms such as Grammarly, Vidio, and Bukalapak. These vulnerabilities, although now addressed, had the potential to compromise user credentials and enable full account takeovers, posing risks to billions of users.

Background on OAuth Hijacking Series

This research paper by Salt Labs marks the final chapter in their OAuth hijacking series, building upon their earlier discoveries of vulnerabilities in platforms like Booking.com and Expo. These flaws presented severe risks, including granting cybercriminals unrestricted access to user accounts, potentially resulting in unauthorized access to sensitive financial and personal information.

Impact on Users

The identified vulnerabilities exposed users to potential identity theft and financial fraud. Cyber attackers could insert a token from another site as a verified token, a technique known as a “Pass-The-Token Attack.” This technique, made possible due to the security flaws in OAuth implementations, enabled hackers to gain unauthorized access to user accounts and sensitive information, jeopardizing user privacy and security.

The platforms mentioned in the Salt Security report, namely Vidio, Bukalapak, and Grammarly, swiftly responded to the research findings and took necessary actions to resolve the security vulnerabilities raised by the researchers at Salt Labs. By addressing these vulnerabilities promptly, the platforms have demonstrated their commitment to user security and protection.

The Scale of the Issue

According to Balmas, a representative from Salt Security, the impact of these vulnerabilities was substantial, potentially affecting over a billion users. The significance of these findings cannot be overstated, as users’ accounts could have been breached had the vulnerabilities been discovered by malicious actors rather than by Salt Labs’ researchers. The proactive actions taken by the affected platforms are commendable, as they helped prevent widespread security incidents.

Introduction to OAuth and Its Design

OAuth is a widely adopted technology that simplifies the sign-in process by allowing users to log in to websites using their social media accounts. It is crucial to note that the research findings do not indicate inherent flaws in the OAuth protocol itself. In fact, OAuth is well-designed and does not exhibit obvious fail points. The flaws discovered by Salt Labs were in the specific implementations of OAuth on the affected platforms.

The research conducted by Salt Security sheds light on critical API security vulnerabilities in the OAuth protocol implementations of popular online platforms. The prompt actions taken by the affected platforms, such as Vidio, Bukalapak, and Grammarly, after being alerted by Salt Labs’ researchers, demonstrate their commitment to user security. As OAuth continues to be a widely adopted technology for user authorization and authentication, these findings highlight the importance of continuous security improvements in online platforms to safeguard user data and protect against potential unauthorized access or data breaches.

It is crucial for both developers and organizations to prioritize ongoing vulnerability assessments and robust security measures in their OAuth implementations. By doing so, they can ensure the safety and privacy of user accounts and prevent potential risks such as identity theft and financial fraud. As the digital landscape continues to evolve, it is imperative that security practices and technologies also evolve to keep pace with emerging threats, ultimately providing users with a secure online experience.

Explore more

Microsoft Is Forcing Windows 11 25H2 Updates on More PCs

Keeping a computer secure often feels like a race against an invisible clock that never stops ticking toward a deadline of obsolescence. For many users, this reality is becoming apparent as Microsoft accelerates the deployment of Windows 11 25H2 to ensure systems remain protected. The shift reflects a broader strategy to minimize the risks associated with running outdated software that

Why Do Digital Transformations Fail During Execution?

Dominic Jainy is a distinguished IT professional whose career spans the complex intersections of artificial intelligence, machine learning, and blockchain technology. With a deep focus on how these emerging tools reshape industrial landscapes, he has become a leading voice on the structural challenges of modernization. His insights move beyond the technical “how-to,” focusing instead on the organizational architecture required to

Is the Loyalty Penalty Killing the Traditional Career?

The golden watch once awarded for decades of dedicated service has effectively become a museum artifact as professional mobility defines the current labor market. In a climate where long-term tenure is no longer the standard, individuals are forced to reevaluate what it means to be loyal to an organization versus their own career progression. This transition marks a fundamental shift

Microsoft Project Nighthawk Automates Azure Engineering Research

The relentless acceleration of cloud-native development means that technical documentation often becomes obsolete before the virtual ink is even dry on a digital page. In the high-stakes world of cloud infrastructure, senior engineers previously spent countless hours performing manual “deep dives” into codebases to find a single source of truth. The complexity of modern systems like Azure Kubernetes Service (AKS)

Is Adversarial Testing the Key to Secure AI Agents?

The rigid boundary between human instruction and machine execution has dissolved into a fluid landscape where software no longer just follows orders but actively interprets intent. This shift marks the definitive end of predictability in quality engineering, as the industry moves away from the comfortable “Input A equals Output B” framework that anchored software development for decades. In this new