Critical API Security Vulnerabilities Found in OAuth Implementations of Popular Platforms

Salt Security’s recent research has uncovered critical API security vulnerabilities in the OAuth protocol implementations of widely used online platforms such as Grammarly, Vidio, and Bukalapak. These vulnerabilities, although now addressed, had the potential to compromise user credentials and enable full account takeovers, posing risks to billions of users.

Background on OAuth Hijacking Series

This research paper by Salt Labs marks the final chapter in their OAuth hijacking series, building upon their earlier discoveries of vulnerabilities in platforms like Booking.com and Expo. These flaws presented severe risks, including granting cybercriminals unrestricted access to user accounts, potentially resulting in unauthorized access to sensitive financial and personal information.

Impact on Users

The identified vulnerabilities exposed users to potential identity theft and financial fraud. Cyber attackers could insert a token from another site as a verified token, a technique known as a “Pass-The-Token Attack.” This technique, made possible due to the security flaws in OAuth implementations, enabled hackers to gain unauthorized access to user accounts and sensitive information, jeopardizing user privacy and security.

The platforms mentioned in the Salt Security report, namely Vidio, Bukalapak, and Grammarly, swiftly responded to the research findings and took necessary actions to resolve the security vulnerabilities raised by the researchers at Salt Labs. By addressing these vulnerabilities promptly, the platforms have demonstrated their commitment to user security and protection.

The Scale of the Issue

According to Balmas, a representative from Salt Security, the impact of these vulnerabilities was substantial, potentially affecting over a billion users. The significance of these findings cannot be overstated, as users’ accounts could have been breached had the vulnerabilities been discovered by malicious actors rather than by Salt Labs’ researchers. The proactive actions taken by the affected platforms are commendable, as they helped prevent widespread security incidents.

Introduction to OAuth and Its Design

OAuth is a widely adopted technology that simplifies the sign-in process by allowing users to log in to websites using their social media accounts. It is crucial to note that the research findings do not indicate inherent flaws in the OAuth protocol itself. In fact, OAuth is well-designed and does not exhibit obvious fail points. The flaws discovered by Salt Labs were in the specific implementations of OAuth on the affected platforms.

The research conducted by Salt Security sheds light on critical API security vulnerabilities in the OAuth protocol implementations of popular online platforms. The prompt actions taken by the affected platforms, such as Vidio, Bukalapak, and Grammarly, after being alerted by Salt Labs’ researchers, demonstrate their commitment to user security. As OAuth continues to be a widely adopted technology for user authorization and authentication, these findings highlight the importance of continuous security improvements in online platforms to safeguard user data and protect against potential unauthorized access or data breaches.

It is crucial for both developers and organizations to prioritize ongoing vulnerability assessments and robust security measures in their OAuth implementations. By doing so, they can ensure the safety and privacy of user accounts and prevent potential risks such as identity theft and financial fraud. As the digital landscape continues to evolve, it is imperative that security practices and technologies also evolve to keep pace with emerging threats, ultimately providing users with a secure online experience.

Explore more

Microsoft Power Platform Modernizes Legacy ERP Systems

The rigid architecture of legacy enterprise resource planning systems has increasingly become a bottleneck for organizations striving to maintain agility in a rapidly evolving digital marketplace. Rather than embarking on the perilous journey of a full-scale platform replacement, forward-thinking enterprises are now embracing a modular strategy known as ERP extension. This methodology leverages the Microsoft Power Platform to bridge the

BlackRock Announces 1-for-3 Reverse Split for Ethereum ETF

The recent decision by BlackRock to implement a one-for-three reverse share split for its iShares Ethereum Trust reflects a strategic recalibration aimed at optimizing the financial product’s market position within the maturing digital asset landscape. As institutional appetite for Ethereum continues to grow throughout 2026 and into the coming years, the necessity for high-liquidity investment vehicles that align with traditional

How Does XCSSET v40 Target the macOS Developer Pipeline?

The traditional assumption that macOS environments remain inherently more secure than their Windows counterparts has been systematically dismantled by the sophisticated evolution of the XCSSET malware suite. This persistent threat specifically targets the very heart of the software supply chain by infiltrating Xcode projects, effectively turning developer workstations into unwitting distributors of malicious code. Version 40 of this campaign demonstrates

Is Windows 11 Pro Worth the Extra Money for You?

Choosing the right version of a modern operating system has evolved into a strategic decision that influences not only the initial cost of a computer but also the long-term functionality of the digital workspace. For many consumers sitting at a retail kiosk or configuring a high-end laptop online, the distinction between Windows 11 Home and its Pro counterpart often feels

How Will the PNLD Data Breach Affect UK Law Enforcement?

The widespread revelation that the Police National Legal Database has suffered a major security compromise represents a significant turning point for the United Kingdom’s law enforcement agencies, signaling a profound shift in how digital vulnerabilities are addressed within the public sector. For years, the PNLD has served as the definitive source for criminal justice legislation, providing thousands of officers with