#phishing
Wiki 1
- OAuth token theft (multilogin + consent phishing) Two post-password-reset attack classes against Google OAuth — refresh-token replay via the undocumented multilogin endpoint, and consent phishing that asks for authorization instead of authentication. Password and 2FA changes don't stop either.