It has been reported that Automattic, the company behind the WordPress.com blogging platform, said it fixed a bug in its official iOS application that might have exposed users’ account authentication tokens to third-party websites.
https://twitter.com/FainPablo/status/1113031537325457408
Expert Comments Below:
Tim Mackey, Senior Technical Evangelist at Synopsys:
Users who have used any form of access token should recognise that changing their password will typically not invalidate access tokens. Instead, they need to revoke application access in order to generate a new token. In the case of a mobile application, uninstalling the application and reinstalling it would typically also generate a new token. The topic of access token management entered public awareness with multiple Facebook breach disclosures in 2018.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.