How to use this reference
Review whether an owned integration preserves the intended app and authorization issuer throughout account linking, including compatibility migrations.
Before reading
- OAuth client and authorization-server roles
- Authorization response and session binding
Context and limits
- Research measurements are historical, not a statement of current vendor exposure.
- The paper reports $35K across multiple vendors; no individual qualifying award is inferred.
- The final PDF exceeded retrieval limits. The official abstract, bibliography and prepublication defense/disclosure sections were reviewed.
Sources and provenance
- Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms USENIX Association · reviewed 2026-10-02
- Publisher-hosted prepublication manuscript USENIX Association · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.