Set as Homepage - Add to Favorites

成人午夜福利A视频-成人午夜福利剧场-成人午夜福利免费-成人午夜福利免费视频-成人午夜福利片-成人午夜福利视

【"musical eroticism in the pastoral world" and eubanks winkler】Enter to watch online.Google patched a major security flaw that could've exposed YouTubers' email addresses

Google has fixed a security flaw that exposed the email addresses of YouTube users,"musical eroticism in the pastoral world" and eubanks winkler a potentially massive privacy breach.

Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.

Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.


You May Also Like

SEE ALSO: Google is reportedly developing a ‘fake’ email feature to help you avoid spam

Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.

Mashable Light Speed Want more out-of-this world tech, space and science stories? Sign up for Mashable's weekly Light Speed newsletter. By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy. Thanks for signing up!

This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.

With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.

Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.


Related Stories
  • Apple Maps follows Google, relabels Gulf of Mexico as America
  • Google: We're not participating in European fact-checking rules for Search or YouTube
  • YouTuber GamersNexus sues Honey over alleged scam

Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."

In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.

0.1212s , 10040.765625 kb

Copyright © 2025 Powered by 【"musical eroticism in the pastoral world" and eubanks winkler】Enter to watch online.Google patched a major security flaw that could've exposed YouTubers' email addresses,First Hand News  

Sitemap

Top 主站蜘蛛池模板: 亚洲国产精品在线观看 | 亚洲天天天 | 国产三级在线 | 日韩在线视频专区免费 | 日韩精品中文在线 | 精品国产网站 | www.日本色色| 日韩精品中文视频 | 一区二区传媒有限公司 | 成人免费视频软件网站 | 日韩精品乱码 | 天天插夜夜爽 | 国产97在线欧洲 | 国产免费看三级片 | 欧美一区二区不卡视频 | 自拍偷拍第五页 | 午夜理伦三级做爰电影 | 日本aⅴ| 成人精品国产亚洲 | 国产ts精品人妖系列 | 亚洲小说区图片区另类 | 欧美在线视频不卡 | 尤物视频网在线观看 | 欧美视频在线一区 | 人妖操伪娘| 爱福利导航| 日韩一区二区超清视频 | 日韩高清乱码在线观看 | 深夜福利无码 | 成人污视频在线观看 | 午夜福利在线影院 | 日韩亚洲产在线观看 | 国产又大又长又爽 | 日韩不卡高清在线观看 | 久久国产不卡视频 | 一区二区在线 | 精品动漫无码 | 日韩无码成人网站 | 色久综合| 日韩视频 中文字幕 | 国产美女视频网站 |