<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Zapier Patched a Five-Flaw Chain That Could Have Compromised Millions of Accounts

Token Security found vulnerabilities in Zapier that could allow account takeover. Zapier quickly patched, with no breaches detected.
Content Team

Security firm Token Security discovered five chained vulnerabilities in Zapier that, together, could have let an attacker take over millions of user accounts — starting with nothing more than a free account.

The attack path ran from a code-writing feature through discarded credentials, into an internal storage system holding over 1,100 private software images. One image contained a publishing key for code running inside every logged-in user's browser — meaning a bad actor could have quietly hijacked automations across Zapier's 8,000+ integrations.

Researchers reported the flaws in February. Zapier triaged within four days, patched within three weeks, and paid the $3,000 maximum bounty. No exploitation was detected.

Source: CyberScoop

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo