Set as Homepage - Add to Favorites

九九视频精品全部免费播放-九九视频免费精品视频-九九视频在线观看视频6-九九视频这-九九线精品视频在线观看视频-九九影院

【korean eroticism movie】Google patched a major security flaw that could've exposed YouTubers' email addresses

Google has fixed a security flaw that exposed the email addresses of YouTube users,korean eroticism movie a potentially massive privacy breach.

Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.

Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.


You May Also Like

SEE ALSO: Google is reportedly developing a ‘fake’ email feature to help you avoid spam

Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.

With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.

Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.


Related Stories
  • Apple Maps follows Google, relabels Gulf of Mexico as America
  • Google: We're not participating in European fact-checking rules for Search or YouTube
  • YouTuber GamersNexus sues Honey over alleged scam

Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."

In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.

0.1417s , 9940.109375 kb

Copyright © 2025 Powered by 【korean eroticism movie】Google patched a major security flaw that could've exposed YouTubers' email addresses,Data News Analysis  

Sitemap

Top 主站蜘蛛池模板: 草草视频手机在线观看视频 | 亚洲无人区码卡二卡三卡四卡 | 亚洲国产不卡一区二区三区 | 成视人a免费观看视频 | 国产午夜亚洲精品理论片八戒 | 99re国产| 欧美.日韩.日本中亚网站 | 日韩亚洲精品不卡在线 | 国产精品自在线拍国产 | 48国产吹潮在线观看 | 成人永久免费视频网站在线观看 | 乌鸦传媒 | 国产精品日韩欧美在线 | 色老成人精 | 国产又粗又猛又爽又黄的视频吉 | 欧洲精品卡1区2卡三卡四卡 | 色就是色亚洲欧洲视频 | 三级全黄的视频在线 | 亚洲精品视频一区二区 | 欧美精品自拍一区 | 得得啪在线视频观看 | 国产免费a视频网站在线观看 | 国产理论在线观看应用 | 免费视频在线观看cc | 亚精区区一区区二在线观看 | 中国字幕在线看韩国电影 | 蜜桃视频一区二区在线观看 | 污污视频在线免费观看 | 国产精品亚洲欧美大片在线看 | 最新热门免费电影 | 日韩国产一区二区三区在线 | 欧美日韩一区二区精美视频 | 亚洲精品中文字幕乱码三区 | 国产偷伦精品视频 | 亚洲黄免费看网站国产福利一区二 | 亚洲精品国产精 | 黑色午夜| 日本高清视频www夜色资源网 | 看一级特黄a大一片电影 | 日本一级a大片在线观 | 欧美性受xxxx黑人xyx性爽 |