Skip to content
Security intelligence

Account takeover research

Everything we have published on Account takeover.

Jun 1, 202611 min

A 1-Click OAuth Token Theft Chain in Bing

Bing for Android shipped four small, individually unremarkable weaknesses. Chained together, a single tap on a link from any web page or another app could steal the victim's Microsoft OAuth refresh token, access tokens, and account PII and send them to an attacker-controlled server.

By Mohamed Sadek

Account takeoverAndroidAouth