CORSLeak: Abusing IAP for a Stealthy Data Exfiltration Attack
ID: 72dd1128-05e2-5fe7-b7bd-46f0db5582de
STIX ID: report--72dd1128-05e2-5fe7-b7bd-46f0db5582de
Feed Name: Mitiga
Mitiga Research demonstrates a cloud misconfiguration attack where an attacker with roles/appengine.deployer in a GCP project can encode sensitive data into App Engine CORS response headers and expose it externally via unauthenticated IAP-forwarded OPTIONS preflight requests. The report outlines the attack flow, prerequisites, limitations (8 KB header limit, deploy quotas), responsible disclosure timeline with Google, and mitigation steps including disabling IAP CORS preflight forwarding, restricting deploy permissions, and monitoring deploy activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
