• News/
  • https://www.bleepingcomputer.com/news/security/google-oauth-flaw-lets-attackers-gain-access-to-abandoned-accounts/

Google OAuth flaw lets attackers gain access to abandoned accounts

BleepingComputer
·
Bill Toulas
·
Published Jan 14, 2025
·
Updated

A weakness in Google’s OAuth “Sign in with Google” feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various software-as-a-service (SaaS) platforms. The security gap was discovered by Trufflesecurity researchers and reported to Google last year on September 30. Google initially disregarded the finding as a “fraud and abuse” issue and not an Oauth or login issue. However, after Dylan Ayrey, CEO and co-founder of Trufflesecurity, presented the issue at Shmoocon last December, the tech giant awarded a $1337 bounty to the researchers and re-opened the ticket. At the time of publishing, though, the issue remains unfixed and exploitable. In a statement for BleepingComputer, a Google spokesperson said that the company recommends customers to follow best practices and "properly close out domains." "We appreciate Dylan Ayrey’s help identifying the risks stemming from customers forgetting to delete third-party SaaS services as part of turning down their operation," a Google representative told BleepingComputer. As a best practice, we recommend customers properly close out domains following these instructions to make this type of issue impossible.  Additionally, we encourage third-party apps to follow best-practices by using the unique account identifiers (sub) to mitigate this risk" - Google spokesperson In a report today, the Ayrey describes the issue as “Google’s OAuth login doesn’t protect against...

Read full article

Affected Software

2 affected components
Google OAuth
Google OAuth
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security flaw in Google's OAuth feature that could allow attackers to access abandoned accounts.

2

What security implications are discussed?

The security implications include potential unauthorized access to sensitive data of former employees linked to SaaS platforms.

3

What products or software are affected?

The affected software includes Google's OAuth service used for signing in with Google.

4

Who discovered the security flaw?

The flaw was discovered by researchers from Trufflesecurity.

5

How are attackers exploiting this vulnerability?

Attackers are exploiting the vulnerability by registering domains for defunct startups to gain access to abandoned accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203