Market Cap: $3.4656T 3.920%
Volume(24h): $135.189B -4.980%
  • Market Cap: $3.4656T 3.920%
  • Volume(24h): $135.189B -4.980%
  • Fear & Greed Index:
  • Market Cap: $3.4656T 3.920%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$99024.587649 USD

3.71%

ethereum
ethereum

$3345.996943 USD

5.06%

xrp
xrp

$2.935810 USD

14.08%

tether
tether

$1.000055 USD

0.04%

bnb
bnb

$702.759353 USD

1.14%

solana
solana

$197.999061 USD

6.40%

dogecoin
dogecoin

$0.373649 USD

6.94%

usd-coin
usd-coin

$1.000052 USD

0.01%

cardano
cardano

$1.060039 USD

9.20%

tron
tron

$0.233181 USD

4.93%

avalanche
avalanche

$39.271326 USD

9.08%

stellar
stellar

$0.479185 USD

14.64%

sui
sui

$4.773555 USD

4.61%

chainlink
chainlink

$21.571027 USD

7.62%

toncoin
toncoin

$5.446006 USD

1.79%

Cryptocurrency News Articles

A Flaw in Google's "Sign in with Google" Authentication Process Could Expose Sensitive User Data

Jan 15, 2025 at 09:04 pm

A significant flaw within OAuth (Open Authorization) via Google's "Sign in with Google" authentication process could expose sensitive user data.

A Flaw in Google's "Sign in with Google" Authentication Process Could Expose Sensitive User Data

A critical vulnerability in OAuth (Open Authorization) via Google's "Sign in with Google" authentication flow can lead to the exposure of sensitive user data. By exploiting a weakness related to domain ownership, attackers can gain unauthorized access to various applications, including critical SaaS platforms.

Discovered by Truffle Security, the vulnerability stems from the ability to purchase domains of failed startups and re-create email accounts once used by former employees. While this doesn't allow access to previous email data, it does enable attackers to utilize these accounts to log in to SaaS products initially accessible with those credentials.

Other compromised platforms include communication, project management, and even interview systems, exposing sensitive business and candidate data to exploitation.

Users can grant websites or applications access to their data from other services such as Google via OAuth without sharing passwords. When using the "Sign in with Google" feature, Google shares key user claims—like email and domain information—with third-party applications to authenticate users.

Problems arise when apps rely solely on these claims for user authentication. If an organization ceases operations and its domain becomes available for purchase, attackers can acquire the domain, re-create email accounts, and use these to regain access to SaaS accounts tied to the defunct domain.

Furthermore, Google's OAuth ID tokens include a unique user identifier—the "sub claim"—that could technically mitigate this vulnerability. However, Truffle found this identifier unreliable in practice. In contrast, Microsoft Entra includes both "sub" and "oid" claims, ensuring an immutable user identifier to prevent such exploits.

This vulnerability affects millions of users across widely adopted SaaS applications such as OpenAI ChatGPT, Slack, Notion, and Zoom. The potential compromise is particularly concerning for accounts linked to HR systems, exposing highly sensitive personal and financial information.

Google initially classified the flaw as "intended behavior" but re-opened the bug report on December 19, 2024, after further evaluation. The tech giant awarded Dylan Ayrey a bounty of $1,337 and has labeled the issue as an "abuse-related methodology with high impact."

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Jan 16, 2025