Demystifying the (In)Security of Oauth-Based Account Linking in Connector Ecosystems
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau
摘要
Modern productivity apps, automation platforms, and AI agents orchestrate across external tools through cloudbased “connectors”. To obtain authorized access to connector accounts, these applications rely extensively on the OAuth 2.0 protocol. However, tracking authorization context across web origins and user-agents, while maintaining the binding to the applications' own user identities (i.e., a secure Account Linking process), pushes OAuth beyond its original client-server model assumptions. The rise of the OAuth-as-a-Service (OaaS) paradigm further complicates trust boundaries in OAuth. In this paper, we present the first comprehensive study of OAuth-based account (mis)linking in connector ecosystems. By systematizing real-world account linking architectural patterns, we show how “OAuth connections”, commonly introduced to manage account linking, can inadvertently break session integrity and security boundaries in OAuth. This enables multiple forms of connector account takeovers. We develop OASIS (OAuth Session Integrity Scanner), an analysis framework that identifies account linking implementations and detects novel Cross-user OAuth session fixation (COSF) vulnerabilities in mobile apps. Our empirical analysis discovers 40 vendors susceptible to COSF and identifies additional Cross-tenant confused deputy threats in 8 OaaS providers. We propose practical countermeasures that have since been adopted by major vendors such as Amazon Bedrock AgentCore. We lead ongoing discussions and standardization efforts to update OAuth security best practices in the IETF.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration PlatformsKaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau 等USENIX Security 2025
- A Comprehensive Formal Security Analysis of OAuth 2.0Daniel Fett, Ralf Küsters, Guido SchmitzCCS 2016 · 被引用 228 次
- C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS CognitoZhen Chen, Ze Jin, Le Gong, Kexin Chen 等S&P 2026
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich 等USENIX Security 2018 · 被引用 63 次
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 被引用 25 次
