Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

How I Found a postMessage Origin Bypass in an OAuth SDK

I spend a lot of time reading other people's code. Not because I enjoy it—though honestly, I kind of do—but because that's where the interesting bugs live.

  • Security researcher found postMessage bypass vulnerability in OAuth SDK
  • Lack of origin check allowed attackers to spoof messages from OAuth popup
  • Adding origin check to message event listener fixed the issue

More from Friday 28 August →