Security researcher Egor Homakov has identified a couple of vulnerabilities that can be exploited to hijack accounts on websites that allow users to authenticate by using their Facebook accounts. Unfortunately, Facebook will not address these issues any time soon.
The first security hole, a CRSF on Facebook.com, can be leveraged by cybercriminals to hijack accounts by replacing the victims identity with their own.
The second flaw is related to the use of ldqu…