Coolblue WebView Auth Token Theft PoC

Click the link below on a device with the Coolblue app installed and logged in:

Open in Coolblue App

The app will open a WebView pointing to the attacker's server. The AccompanistAuthenticatedWebViewClient will replay the request through OkHttp with the user's Authorization: Bearer CB-<token> header attached.