Exposing Millions via Failed Startup Domains: Vulnerability in Google OAuth Uncovered

A recent study has revealed a loophole in Google’s authentication process known as “Sign in with Google,” which capitalizes on a peculiarity in domain ownership to infiltrate and obtain confidential information.

A recent study has revealed a loophole in Google’s authentication process known as “Sign in with Google,” which capitalizes on a peculiarity in domain ownership to infiltrate and obtain confidential information.
According to Dylan Ayrey, the co-founder and CEO of Truffle Security, “Google’s OAuth authentication is inadequate in preventing an individual from acquiring a failed startup’s domain and leveraging it to recreate email accounts belonging to past employees.”

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.