/sign-in in their browser.accounts.google.com./callback./callback endpoint uses a deep link to return to the mobile app and deliver the session cookie.example-service.com and register example-service:// in my own app, couldn’t my app hijack the callback and steal the session cookie from the legitimate app?