A flaw in Google OAuth system is exposing millions of users via abandoned accounts
January 15, 2025

A flaw in Google OAuth system is exposing millions of users via abandoned accounts


  • Study finds that purchasing domains from shuttered businesses can provide access to their SaaS accounts
  • Google says this is not a vulnerability and that companies should make sure they don’t leave sensitive information behind.
  • Researchers suggest additional safety measures

Experts found a vulnerability in GoogleOAuth “Sign in with Google” feature, which could allow attackers to access sensitive data belonging to closed businesses.

Google has acknowledged the bug but isn’t doing much to fix it, rather saying that businesses should ensure the security of the data they leave behind.

2025-01-15 16:03:00

Leave a Reply

Your email address will not be published. Required fields are marked *