logo

CORSLeak: Abusing IAP for a Stealthy Data Exfiltration Attack

ID: 72dd1128-05e2-5fe7-b7bd-46f0db5582de

STIX ID: report--72dd1128-05e2-5fe7-b7bd-46f0db5582de

Feed Name: Mitiga

Threat Score
65/100

Date Published: 2026-07-16

Date Updated: 2026-07-29

...
...

Mitiga Research demonstrates a cloud misconfiguration attack where an attacker with roles/appengine.deployer in a GCP project can encode sensitive data into App Engine CORS response headers and expose it externally via unauthenticated IAP-forwarded OPTIONS preflight requests. The report outlines the attack flow, prerequisites, limitations (8 KB header limit, deploy quotas), responsible disclosure timeline with Google, and mitigation steps including disabling IAP CORS preflight forwarding, restricting deploy permissions, and monitoring deploy activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.