Tech

A flaw in Google OAuth system is exposing millions of users via abandoned accounts

Share
Share


  • Buying domains from businesses that shut down could grant access to their SaaS accounts, research finds
  • Google argues it’s not a vulnerability, and that businesses should make sure they’re not leaving sensitive information behind
  • Researchers propose additional safeguards

Experts have found a vulnerability in Google’s OAuth “Sign in with Google” feature which could allow malicious actors to access sensitive data belonging to businesses that have shut down.

Google acknowledged the flaw, but is not doing much to address it, rather saying that it is up to the businesses to ensure the security of the data they are leaving behind.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
DeepSeek sees surge in developer use as 3 in 10 businesses adopt the controversial LLM provider
Tech

DeepSeek sees surge in developer use as 3 in 10 businesses adopt the controversial LLM provider

Developers shift from loyalty to flexibility as OpenAI leads, but DeepSeek gains...

China’s CATL launches new EV sodium battery
Tech

China’s CATL launches new EV sodium battery

Chinese battery giant CATL has launched a new sodium-ion battery it says...

Synology confirms it is cracking down on third-party NAS hard drives
Tech

Synology confirms it is cracking down on third-party NAS hard drives

Synology’s 2025 Plus range only works with certain hard drives It says...