Youssef Sammouda 14
- DOM-XSS in Instant Games due to improper verification of supplied URLs
- Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing
- Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing
- Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
- Multiple bugs chained to takeover Facebook Accounts which uses Gmail.
- More secure Facebook Canvas Part 2: More Account Takeovers
- Multiple bugs allowed malicious Android Applications to takeover Facebook/Workplace accounts
- Multiple bugs allowed malicious Android Applications to takeover Facebook/Workplace accounts
- More secure Facebook Canvas : Tale of $126k worth of bugs that lead to Facebook Account Takeovers
- Oversightboard.com site-wide CSRF due to missing checking
- Disclose unconfirmed email/phone of a Facebook user
- Disclose unconfirmed email/phone of a Facebook user
- Oculus SSO “Account Linking” bug leads to account takeover on third party websites and inside VR Games/Apps
- Oculus SSO “Account Linking” bug leads to account takeover on third party websites and inside VR Games/Apps