БЛОГ

Jan 15, 2025

Google OAuth flaw lets attackers gain access to abandoned accounts

Posted by in category: security

A weakness in Google’s OAuth “Sign in with Google” feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various software-as-a-service (SaaS) platforms.

The security gap was discovered by Trufflesecurity researchers and reported to Google last year on September 30.

Google initially disregarded the finding as a “fraud and abuse” issue and not an Oauth or login issue. However, after Dylan Ayrey, CEO and co-founder of Trufflesecurity, presented the issue at Shmoocon last December, the tech giant awarded a $1337 bounty to the researchers and re-opened the ticket.

Leave a reply