witter iOS fails to validate server certificate and sends OAuth token

Smart devices software vulnerabilities
Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

witter iOS fails to validate server certificate and sends OAuth token

Post by Shane1145 »

The issue "Twitter iOS fails to validate server certificate and sends OAuth token" highlights a significant security flaw where the app does not properly validate the authenticity of the server it connects to. As a result, this vulnerability can expose sensitive OAuth tokens to potential interception by malicious actors, risking unauthorized access to user accounts.

https://hackerone.com/reports/168538
Post Reply