Salt Security researchers detail how now-patched critical API flaws in the social sign-in and OAuth implementations affected Vidio, Grammarly, and Bukalapak
Context & Ripple Effects
The report places OAuth and social sign-in implementations under the same scrutiny previously applied to enterprise federation: a SAML single-sign-on flaw that enabled account impersonation showed how defects at the authentication layer can bypass an application's normal password controls.
It also reinforces the operational importance of confirming remediation, not merely publishing a fix; prior coverage of MuleSoft emphasized proactive patch verification with customers after disclosure of a critical flaw.
First-order effects
- Vidio, Grammarly, and Bukalapak must ensure the reported fixes are deployed across the affected social-login and OAuth paths, then assess whether the flaws could have exposed account-access or authorization flows before patching.
- Salt Security's findings give the affected companies and their security teams a concrete basis to review API authentication logic rather than treating OAuth provider integration as a one-time setup.
Second-order effects
- Other consumer services using similar social sign-in patterns face pressure to test token validation, redirect handling, and API authorization boundaries, particularly where third-party identity is translated into an application session.
- Security vendors and application teams gain another reason to make identity-flow testing part of recurring API security review, alongside vulnerability disclosure and patch follow-through.
Third-order effects
- If this pattern persists, API security programs will increasingly treat OAuth and federated login as continuously monitored application logic rather than as trusted plumbing supplied by an identity provider.
- The durable shift is toward closed-loop application security: discovery, validation, remediation, and verification must cover identity integrations as well as conventional API endpoints.
The trend: OAuth and social-login integrations are becoming a core API-security attack surface, pushing organizations toward continuous testing of authentication and authorization flows.