OAuth Device Flow Vulnerabilities: Analysis of 2024-2025 Attack Wave(guptadeepak.com)
guptadeepak.com
OAuth Device Flow Vulnerabilities: Analysis of 2024-2025 Attack Wave
https://guptadeepak.com/oauth-device-flow-vulnerabilities-a-critical-analysis-of-the-2024-2025-attack-wave/
The critical issue stems from attacker exploitation of insufficient user code verification and token issuance processes, enabling device flow hijacking and abuse at scale. Notably, the challenge of securely binding device codes to legitimate users remains unresolved, especially in constrained input environments.
How are you addressing the trade-offs between user convenience and security in OAuth device flows?