Sign in. It’s quick, free and it’s up to you.
An account is an optional way to support the work we do. Find out more.
Sign in. It’s quick, free and it’s up to you.
An account is an optional way to support the work we do. Find out more.
A MAJOR GOOGLE security hole that allows a person’s email address to be accessed has been uncovered, according to TechCrunch.
The breach allowed the emails address of “anyone already signed into Google” to be accessed, according to the report.
The man who uncovered the security issue was using the site http://guntada.blogspot.com (which has now been taken down) to ‘harvest’ the emails of people signed into a Google account. The man, identifed as Vahe G, told TechCrunch that he tried to contact Google but they would not respond to his emails.
Google says the issue is now resolved:
We quickly fixed the issue in the Google Apps Script API that could have allowed for emails to be sent to Gmail users without their permission if they visited a specially designed website while signed into their account. We immediately removed the site that demonstrated this issue, and disabled the functionality soon after. We encourage responsible disclosure of potential application security issues to security@google.com.
To embed this post, copy the code below on your site
have your say