A weakness in Google’s OAuth “Sign in with Google” feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various software-as-a-service (SaaS) platforms. The security gap was discovered by Trufflesecurity researchers and reported to Google last year on September 30. Google initially disregarded the finding as a “fraud and abuse” issue and not an Oauth or login issue. However, after Dylan Ayrey, CEO and co-founder of Trufflesecurity, presented the issue at Shmoocon last December, the tech giant awarded a $1337 bounty to the researchers and re-opened the ticket. At the time of publishing, though, the issue remains unfixed and exploitable. In a statement for BleepingComputer, a Google spokesperson said that the company recommends customers to follow best practices and "properly close out domains." "We appreciate Dylan Ayrey’s help identifying the risks stemming from customers forgetting to delete third-party SaaS services as part of turning down their operation," a Google representative told BleepingComputer. As a best practice, we recommend customers properly close out domains following these instructions to make this type of issue impossible. Additionally, we encourage third-party apps to follow best-practices by using the unique account identifiers (sub) to mitigate this risk" - Google spokesperson In a report today, the Ayrey describes the issue as “Google’s OAuth login doesn’t protect against...
Google OAuth flaw lets attackers gain access to abandoned accounts
BleepingComputer
·Bill Toulas
·Published Jan 14, 2025
·Updated
Affected Software
2 affected components
Google OAuth
Google OAuth
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security flaw in Google's OAuth feature that could allow attackers to access abandoned accounts.
2
What security implications are discussed?
The security implications include potential unauthorized access to sensitive data of former employees linked to SaaS platforms.
3
What products or software are affected?
The affected software includes Google's OAuth service used for signing in with Google.
4
Who discovered the security flaw?
The flaw was discovered by researchers from Trufflesecurity.
5
How are attackers exploiting this vulnerability?
Attackers are exploiting the vulnerability by registering domains for defunct startups to gain access to abandoned accounts.