1-Click Account Takeover — Immutable Passport
XSS on biome-storybook.immutable.com → OAuth code theft via auth.immutable.com/im-logged-in open redirect → token exchange → full ATO
Chain: postMessage XSS → cookie theft → OAuth authorization code theft → token exchange → ATO
Interaction: 1-click (button to start the OAuth redirect)
Impact: Attacker obtains
Interaction: 1-click (button to start the OAuth redirect)
Impact: Attacker obtains
access_token (scope: transact) + refresh_token (persistent access) + id_token (PII: email, wallet addresses)
Attack Controls
Exfiltrated Data
Storybook iframe (hidden in real attack)