DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A security auditor is reviewing an application that uses OAuth 2.0 for API authorization. The application stores the access token directly in the client's browser local storage after a successful authorization flow. What is the primary security risk associated with this practice?

  1. ACross-Site Request Forgery (CSRF) attacks
  2. BSession fixation vulnerabilities
  3. CInsufficient logging and monitoring
  4. DCross-Site Scripting (XSS) attacks
Show answer & explanation

Correct answer: D. Cross-Site Scripting (XSS) attacks

Storing access tokens in browser local storage makes them vulnerable to Cross-Site Scripting (XSS) attacks. If an attacker successfully injects malicious script, they can easily access and steal the token from local storage, compromising the user's session.

Why the other options are wrong

  • A. CSRF attacks target state-changing requests and are often mitigated by anti-CSRF tokens, not directly related to token storage location.
  • B. Session fixation involves an attacker fixing a user's session ID, which is not the primary risk of local storage token exposure.
  • C. Insufficient logging is a general security weakness but not the direct, specific risk of storing tokens in client-side local storage.

XSS and Local Storage

Cross-Site Scripting (XSS) is a vulnerability that allows attackers to inject client-side scripts into web pages. If sensitive data like access tokens are stored in browser local storage, an XSS attack can steal them.

  • Local storage is accessible via JavaScript.
  • XSS allows malicious JavaScript injection.
  • Stolen tokens can be used to impersonate the user.

Memory trick: OAuth Tokens: Store Safely, Or XSS Steals Easily.

More Understanding and Using APIs questions