MRMohammad Reza Mirzadzareinblog.mirzadzare.net·Feb 20 · 7 min readIP Spoofing to Account Takeover: You Patched It? Really?Abstract In my previous article, I described how I found a security flaw in a popular desktop app's OAuth flow that allowed me to steal any user's account with just one click. I reported it, saw it pa00
MRMohammad Reza Mirzadzareinblog.mirzadzare.net·Dec 1, 2025 · 9 min readFrom "Log in with OAuth" to "Your Account Is Mine" – Desktop App EditionAbstract Just one click on a malicious link → account takeover. No phishing, no malware. I discovered a security flaw in a popular desktop app’s OAuth flow that let me steal any user’s account just 02VM