Salt Labs identifies OAuth security flaw within Booking.com

Security flaw in Booking.com OAuth implementation could be used to launch account takeovers, but researchers discovered and flagged the issue before it could be exploited in the wild

Sebastian Klovig Skelton

By

Published: 02 Mar 2023 13:00

Critical security flaws in Booking.com’s implementation of Open Authorization (OAuth) could have enabled attackers to launch large-scale account takeovers, putting millions of people’s sensitive personal data at risk, finds threat research by Salt Labs.

An industry-standard social login protocol, OAuth allows users to log in to sites via their social media accounts, but by manipulating certain steps in Booking.com’s authorisation sequence, Salt Labs researchers found they could hijack sessions and conduct account takeovers.

Gaining complete control of people’s accounts in this way would have enabled attackers to leak personal identifiable information and other sensitive user data, as well as perform any action on behalf of the user, including making bookings or cancellations.

The researchers said that anyone configured to log in to Booking.com via Facebook would have been vulnerable and that – given the popularity of the feature and the fact that the site has up to 500 million visitors each month – millions could have been affected by a successful exploit.

The threat was compounded by the fact that attackers could then use the compromised Booking.com login to gain access to sister company’s Kayak.com user accounts.

“OAuth has quickly become the industry standard and is currently in use by hundreds of thousands of services around the world,” said Yaniv Balmas, vice-president of research at Salt Security.

“As a result, misconfigurations of OAuth can have a significant impact on both companies and customers as they leave precious data exposed to bad actors. Security vulnerabilities can happen on any website, and as a result of rapid scaling, many organisations remain unaware of the myriad of security risks that exist within their platforms.”

Upon discovering the vulnerabilities, Salt Labs – the research arm of application programming interface (API) security company Salt Security – followed coordinated disclosure practices with Booking.com, and all issues were remediated. There is no evidence of the flaws having been exploited in the wild.

“On receipt of the report from Salt Security, our teams immediately investigated the findings and established that there had been no compromise to the Booking.com platform, and the vulnerability was swiftly resolved,” said a Booking.com spokesperson.

“We take the protection of customer data extremely seriously. Not only do we handle all personal data in line with the highest international standards, but we are continuously innovating our processes and systems to ensure optimal security on our platform, while evaluating and enhancing the robust security measures we already have in place.

“As part of this commitment, we welcome collaboration with the global security community, and our Bug Bounty Programme should be utilised in these instances.”

The researchers have also published a detailed technical breakdown of the vulnerability and how it was exploited, which runs through how they were able to string together three sperate security issues to achieve account takeovers.

“The vulnerability described in this document is a combination of three minor security gaps. Most of the focus is on the first security gap, which allows the attacker to choose another path for the redirect_uri,” they said.

“When you do an integration with Facebook or another vendor, it’s extremely important to provide hard-coded paths for the redirect_uri in the Facebook configuration.”

According to the Salt security state of API security report, Q3 2022, Salt customers experienced a 117% increase in API attack traffic while their overall API traffic grew 168%

The growth trend has seen an increasing number of high-profile incidents linked to API traffic this year, including the recent attack on Australian telco Optus, which saw names, addresses, dates of birth, phone numbers, email addresses, and driving licence and passport data relating to 11 million customers stolen and held to ransom – an incident so serious in its scope that the Australian government is now planning to amend its telecoms security regulations.

Read more on Business applications

Read More
Dion Pecora

Latest

SkyCity to Pay $15M Settlement Over Regulatory Breaches in Australian Casino

SkyCity Entertainment Group has reached a settlement requiring it to pay AUD 21 million (about $14.72 million) in relation to compliance breaches at its casino in Adelaide, Australia. The settlement is part of a larger deal with the Commissioner for Liquor and Gambling in South Australia, addressing regulatory concerns for SkyCity’s Adelaide casino in an

Interview: Emmanuel Frenehard, chief digital officer, Sanofi

Emmanuel Frenehard, chief digital officer (CDO) at biopharmaceutical giant Sanofi, recognises that the CDO role often means different things in different companies. At Sanofi, it was decided that the role would be an all-encompassing position, overseeing business applications, infrastructure, cyber security, data, artificial intelligence (AI) and digital services. There are also professionals in Frenehard’s team

Jim Carrey Returning for The Grinch Sequel Movie

Why Jim Carrey Almost Quit The Grinch & Gave Back $20 Million Salary Pucker up, Whoville—the Grinch is coming back. Indeed, director Ron Howard and his producing partner Brian Grazer ’s production company Imagine Entertainment confirmed on Instagram June 18 that a sequel to Jim Carrey ’s 2000 movie How the Grinch Stole Christmas is

Ojakalasi – Intandane

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

SkyCity to Pay $15M Settlement Over Regulatory Breaches in Australian Casino

SkyCity Entertainment Group has reached a settlement requiring it to pay AUD 21 million (about $14.72 million) in relation to compliance breaches at its casino in Adelaide, Australia. The settlement is part of a larger deal with the Commissioner for Liquor and Gambling in South Australia, addressing regulatory concerns for SkyCity’s Adelaide casino in an

Interview: Emmanuel Frenehard, chief digital officer, Sanofi

Emmanuel Frenehard, chief digital officer (CDO) at biopharmaceutical giant Sanofi, recognises that the CDO role often means different things in different companies. At Sanofi, it was decided that the role would be an all-encompassing position, overseeing business applications, infrastructure, cyber security, data, artificial intelligence (AI) and digital services. There are also professionals in Frenehard’s team

Jim Carrey Returning for The Grinch Sequel Movie

Why Jim Carrey Almost Quit The Grinch & Gave Back $20 Million Salary Pucker up, Whoville—the Grinch is coming back. Indeed, director Ron Howard and his producing partner Brian Grazer ’s production company Imagine Entertainment confirmed on Instagram June 18 that a sequel to Jim Carrey ’s 2000 movie How the Grinch Stole Christmas is

Ojakalasi – Intandane

MusicDOWNLOAD MP3 SONG...

Ojakalasi – Move On Ft Bhambatha

MusicDOWNLOAD MP3 SONG...

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID