I could not sleep, so I wrote an article in English.
Please have a look if you are interested:
Relationship between OAuth and CX, and OAuth vulnerability
Incidentally, CX is not affected by this attack. Also, I have a feeling that the FIX being considered for OAuth does not address the fundamental issue…
Related posts

OAuth PKCE Published as RFC7636
OAuth PKCE (pronounced “pixy”), for which John Bradley (Ping), Naveen Agarwal (Google), and I are credited as co-authors, has been published as [RFC 7636]. It was…

Future-Proofing OAuth Security—OAuth Security Workshop 2017
OAuth Security Workshop 2017, where I gave a presentation. (2017/7/14) Since Professor Basin (ETH Zurich) and Professor Cremers (University of Oxford) were both going to be…

Using Plain OAuth 2.0 for Authentication Opens a Security Hole Big Enough to Drive a Car Through
Using the OAuth 2.0 implicit grant flow for authentication opens a security hole big enough to drive a car through, as explained in this excellent article…
