X app approvals can bypass password and 2FA, security thread warns

eyishazyer · x · 2026-09-19

A security thread on X account weaknesses highlights a documented phish: in September 2025, Zak Cole showed a DM phish where the preview displayed a real t.co link over a lookalike domain, followed by a genuine X consent screen for a fake Calendar app using Cyrillic lookalike letters — approving it reportedly bypassed password and 2FA.

Other points:

Related event: X OAuth Phishing Can Bypass 2FA and Access DMs(2 posts)→

Original post →

More from Safety

Safety channel →