Set as Homepage - Add to Favorites

日韩欧美成人一区二区三区免费-日韩欧美成人免费中文字幕-日韩欧美成人免费观看-日韩欧美成人免-日韩欧美不卡一区-日韩欧美爱情中文字幕在线

【hd ??? ??】Google patched a major security flaw that could've exposed YouTubers' email addresses

Google has fixed a security flaw that exposed the email addresses of YouTube users,hd ??? ?? a potentially massive privacy breach.

Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.

Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.


You May Also Like

SEE ALSO: Google is reportedly developing a ‘fake’ email feature to help you avoid spam

Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.

With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.

Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.


Related Stories
  • Apple Maps follows Google, relabels Gulf of Mexico as America
  • Google: We're not participating in European fact-checking rules for Search or YouTube
  • YouTuber GamersNexus sues Honey over alleged scam

Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."

In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.

0.1201s , 9714.734375 kb

Copyright © 2025 Powered by 【hd ??? ??】Google patched a major security flaw that could've exposed YouTubers' email addresses,Public Opinion Flash  

Sitemap

Top 主站蜘蛛池模板: 国产成人综合自拍 | tv香蕉人人网站 | 无码a√毛片一区二区三区视免 | 波多野结衣中文久久精品伊人 | 2024国自拍产精品视频 | 精品人妻午夜一区二区三区四 | 国产精品一区久久精品 | 国产亚洲精品第一综合另类 | 九九自拍 | 免费一区在线观看 | 久久久久久免费一区二区三区 | 免费人成在线观看网站品爱网 | 麻豆精品人妻一区二 | 自拍亚洲中文字幕一区二区 | 久久在线播放视频 | 国产三级一二三四五区不卡免费在线观看 | 欧美在线视频播放一区二区三区 | 激情综合婷婷丁香五月合色字幕 | 日产精品一二三四区气温 | 高清最新av网站 | 丁香五月婷婷中文无码精品 | 国产高清不卡专区在线观看 | 一区二区三区毛AAAA片特级 | 69成人免费视频无码专区 | 成年美女黄网色大观看全 | 亚洲无专砖码直接进入 | 99成人精品一区二区 | 99精品人妻视频一区 | 成人影院YY111111在线 | 熟女人妇成熟妇女系列视频 | 少妇性BBB搡BBB爽爽爽四川 | 国产又色又爽又黄的视频免费看 | 69堂无码国产精品色四婷婷专区 | 二区天堂国产成人无码精品久久久露 | 国产精品亚洲欧美高清亚洲综合 | 日本公妇里乱片A片在线播放保姆 | 国产做a爱免费视频在线 | 国产成人精品手机在线观看 | 免费看一级高潮毛片高清a 免费看一区二区三区 | 欧美成人精品手机在线 | 视频一本大道香蕉久在线播放 |