Lune

S&P2026顶会

Demystifying the (In)Security of Oauth-Based Account Linking in Connector Ecosystems

Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau

2026年份

摘要

Modern productivity apps, automation platforms, and AI agents orchestrate across external tools through cloudbased “connectors”. To obtain authorized access to connector accounts, these applications rely extensively on the OAuth 2.0 protocol. However, tracking authorization context across web origins and user-agents, while maintaining the binding to the applications' own user identities (i.e., a secure Account Linking process), pushes OAuth beyond its original client-server model assumptions. The rise of the OAuth-as-a-Service (OaaS) paradigm further complicates trust boundaries in OAuth. In this paper, we present the first comprehensive study of OAuth-based account (mis)linking in connector ecosystems. By systematizing real-world account linking architectural patterns, we show how “OAuth connections”, commonly introduced to manage account linking, can inadvertently break session integrity and security boundaries in OAuth. This enables multiple forms of connector account takeovers. We develop OASIS (OAuth Session Integrity Scanner), an analysis framework that identifies account linking implementations and detects novel Cross-user OAuth session fixation (COSF) vulnerabilities in mobile apps. Our empirical analysis discovers 40 vendors susceptible to COSF and identifies additional Cross-tenant confused deputy threats in 8 OaaS providers. We propose practical countermeasures that have since been adopted by major vendors such as Amazon Bedrock AgentCore. We lead ongoing discussions and standardization efforts to update OAuth security best practices in the IETF.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖