Collected research
Mobile OAuth Attacks - iOS URL Scheme Hijacking Revamped
Revisits iOS OAuth URL-scheme hijacking and shows how a malicious application can claim another app's custom callback scheme. Silent authorization behavior can then deliver an OAuth response to the attacker without a conspicuous user prompt.
Record
- Researcher
- Evan Connelly
- Published by
- Evan Connelly
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Evan Connelly, first published at the original source. Preserved copies are kept so the citation survives its host.