logo

New Google Cookies Exploit Allows Access After Password Reset

ID: 2d8cfc77-9515-5399-89bb-da3e75c38cfc

STIX ID: report--2d8cfc77-9515-5399-89bb-da3e75c38cfc

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2024-01-03

Date Updated: 2026-04-22

Author: Tushar Subhra Dutta

...
...

CloudSEK and community reporting detail an undocumented Google OAuth "MultiLogin" endpoint abused to regenerate authentication cookies that remain valid after password resets; the technique was discovered by PRISMA and has been incorporated into the Lumma Infostealer, enabling persistent, stealthy account takeover by extracting Chrome's token_service data and decrypting tokens via the browser Local State key.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.