Web Hack List

Preliminary research

Demystifying the (In)Security of OAuth-based Account Linking in Connector Ecosystems

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Project page for a systematic study of OAuth connector account linking. It links the paper analyzing cross-user session fixation and connector or tenant confusion, alongside an Android static-analysis screening method and deployment validation. Earlier attack disclosures are distinguished from the later measurement study.

Record

Researcher
Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung and Wing Cheong Lau
Published by
The Chinese University of Hong Kong
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung and Wing Cheong Lau, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .