Stealing Facebook OAuth Code Through Screenshot viewer
Medium
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
In this report, the researcher demonstrated a way to combine multiple vulnerabilities to potentially allow an attacker to extract Oauth tokens from a victim's session. This was done by taking advantage of an image injection vulnerability in the Screenshot Viewer utility as well as additional vulnerabilities still being resolved. Combining these vulnerabilities allowed for an impact greater than the individual impact of each issue on their own. We have resolved the image injection vulnerability, thereby preventing the potential exfiltration of sensitive authentication tokens.
Actions:
Reported by
netfuzzer
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure