The victim has a legitimate verified account. The service silently merges any SSO provider that asserts the same email - no re-authentication, no consent prompt, no notification.
Attacker precondition: the ability to issue an OAuth token for the victim's email at any SSO provider the service trusts:
The attack only needs to work at one provider. Every SSO option added is another permanent trust delegation on every account - including accounts that never used that provider.
Create a legitimate account with email and password.
The attacker does not touch the target service. They only need access at one of the providers it trusts. Pick a scenario:
As a provider insider with token-issuance access:
Via a provider breach or token forgery: