Security researcher Nir Goldshlager, known to us from a previous post, managed to identify yet another vulnerability in Facebook OAuth that can be exploited to gain access to any account.
In the previous attack method he presented last February, the expert used the Facebook Messenger APP_ID to gain full access to any account he wanted.
Facebook addressed the issue and made changes to the protection using regex, but Goldshlager reports that he discovered a new method that allows him to exploit the Facebook Messenger APP_ID.
In addition to this vulnerability, he has also found another way that allows him to bypass OAuth regex protection, but the second method only works for attacks against Facebook members using Firefox.
Both security issues have been fixed by Facebook immediately after they were reported.
Full technical details of the vulnerability are available on Nir Goldshlager's blog.

