New Google Cookies Exploit Allows Access After Password Reset
ID: 2d8cfc77-9515-5399-89bb-da3e75c38cfc
STIX ID: report--2d8cfc77-9515-5399-89bb-da3e75c38cfc
Feed Name: GBHackers
Threat Score
CloudSEK and community reporting detail an undocumented Google OAuth "MultiLogin" endpoint abused to regenerate authentication cookies that remain valid after password resets; the technique was discovered by PRISMA and has been incorporated into the Lumma Infostealer, enabling persistent, stealthy account takeover by extracting Chrome's token_service data and decrypting tokens via the browser Local State key.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
