A flaw in Google OAuth system is exposing millions of users via abandoned accounts

Estimated read time 3 min read


  • Buying domains from businesses that shut down could grant access to their SaaS accounts, research finds
  • Google argues it’s not a vulnerability, and that businesses should make sure they’re not leaving sensitive information behind
  • Researchers propose additional safeguards

Experts have found a vulnerability in Google’s OAuth “Sign in with Google” feature which could allow malicious actors to access sensitive data belonging to businesses that have shut down.

Google acknowledged the flaw, but is not doing much to address it, rather saying that it is up to the businesses to ensure the security of the data they are leaving behind.

Source link

You May Also Like

More From Author

+ There are no comments

Add yours