vulns.co
/
GKData.io MCP

USENIX Association · 1 min read

Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms

Studies account linking across multi-app integration platforms and identifies inconsistent app identity as a trust-boundary problem. Proposes app-specific authorization-context binding.

Open the reference Research PaperReviewed 2026-10-02

How to use this reference

Review whether an owned integration preserves the intended app and authorization issuer throughout account linking, including compatibility migrations.

Before reading

  • OAuth client and authorization-server roles
  • Authorization response and session binding

Context and limits

  • Research measurements are historical, not a statement of current vendor exposure.
  • The paper reports $35K across multiple vendors; no individual qualifying award is inferred.
  • The final PDF exceeded retrieval limits. The official abstract, bibliography and prepublication defense/disclosure sections were reviewed.

Sources and provenance

  1. Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms USENIX Association · reviewed 2026-10-02
  2. Publisher-hosted prepublication manuscript USENIX Association · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software