Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 27 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Salt Security Discovers Flaws in Social Login Mechanism Impacting Thousands of Websites and Exposing Billions of Users to Account Takeover

API security vulnerabilities found in OAuth protocol implementations of Grammarly, Vidio, and Bukalapak have been remediated, but similar issues may impact other sites

by Guru Writer
October 24, 2023
in News
Purple Logo, capitalised letters: SALT.
Share on FacebookShare on Twitter
Today, API security company Salt Security released new threat research from Salt Labs highlighting API security vulnerabilities uncovered in the social sign-in and Open Authentication (OAuth) implementations of multiple online companies, including Grammarly, Vidio, and Bukalapak. The flaws, which have since been remediated, could have allowed for credential leakage and enabled full account takeover (ATO). Salt Labs also reported that 1000s of other websites using social sign-in mechanisms are likely vulnerable to the same type of attack, putting billions of individuals around the globe at risk.
These findings mark the third and final research report in the Salt Labs OAuth hijacking series, following vulnerabilities uncovered in Booking.com and Expo earlier this year.
This latest research identified flaws in the access token verification step of the social sign-in process, part of the OAuth implementation on these websites. The vulnerabilities could have impacted nearly a billion user accounts across these three sites.
The vulnerabilities identified could allow cyber criminals to gain complete access to a user’s accounts on dozens of websites, potentially allowing access to sensitive data. Additionally, cybercriminals may have been able to perform any action on behalf of that user which may lead to identity theft and financial fraud.
Favoured across many websites and web services, OAuth enables a “one-click” login that lets users tap their social media accounts, such as Google or Facebook, to verify their identity and register on a site rather than set up a unique username/password combination for access. For this type of login, OAuth needs a verified token to approve access, and all three sites failed to verify the token. As a result, the Salt Labs researchers were able to insert a token from another site as a verified token and gain access to user accounts – using a technique called “Pass-The-Token Attack.”
“OAuth is one of the fastest adopted technologies in the AppSec domain and has quickly become one of the most popular protocols for both user authorisation and authentication,” said Yaniv Balmas, VP of Research, Salt Security. “The Salt Labs research illustrates the potential impacts that OAuth implementation issues can have on a business and its customers. We hope this series has helped educate the broader industry on the nature of potential OAuth implementation errors and how to close these API-based security gaps to better protect data and use OAuth more securely.”
Bukalapak
Bukalapak is one of Indonesia’s largest and most prominent eCommerce platforms, with more than 150 million monthly users.
Bukalapak didn’t verify the access token when users registered using a social login. Therefore, by inserting a token from another website, the Salt Labs team could access a user’s credentials in bukalapak.com and completely take over that user’s account.
Vidio
Vidio, an online video streaming platform with 100M monthly active users, offers a range of content, including movies, TV shows, live sports, and original productions.
Salt Labs’ researchers discovered OAuth security vulnerabilities when logging in through Facebook. Because the Vidio.com site did not verify the token, which the website developers must do, and not OAuth itself, an attacker could manipulate the API calls to insert an access token generated for a different application. This alternate token/AppID combination allowed the Salt Labs research team to impersonate a user on the Vidio site, which would have allowed massive account takeover on thousands of accounts.
Grammarly
Grammarly.com is an AI-powered writing tool that helps users improve their writing by offering grammar, punctuation, spelling checks, and other writing tips to more than 30 million daily users.
By doing reconnaissance on the API calls and learning the terminology the Grammarly site uses to send the code, the Salt Labs team was able to manipulate the API exchange to insert code used to verify users on a different site and, again, obtain the credentials of a user’s account and achieve full account takeover.
Crucially, upon discovering the vulnerabilities on all three sites, Salt Labs’ researchers followed coordinated disclosure practices, and all issues have been remediated.
The full report, including how Salt Labs conducted this research and steps for mitigation, is available here.
ShareTweet
Previous Post

In Conversation With Ilona Simpson, CIO EMEA at Netskope

Next Post

Cato Vice President to Speak About Collaboration on SASE Projects at Gartner IT Symposium/XPO 2023, Barcelona, Spain

Recent News

Keeper Security launches Microsoft Teams integration for privileged access management

Keeper Security launches Microsoft Teams integration for privileged access management

June 26, 2026
UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol