OAuth redirect_uri Hijacking: Stealing Tokens Through a Loose Redirect
When an OAuth provider validates redirect_uri loosely, the authorization code meant for the real app is delivered to an attacker. Here is how the bypass works and how exact matching, PKCE and state shut it down.