Expo SDK has an OAuth vulnerability
Critical severity
GitHub Reviewed
Published
Apr 24, 2023
to the GitHub Advisory Database
•
Updated Oct 15, 2025
Description
Published by the National Vulnerability Database
Apr 24, 2023
Published to the GitHub Advisory Database
Apr 24, 2023
Reviewed
Oct 15, 2025
Last updated
Oct 15, 2025
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).
References