logo

Google OAuth flaw lets attackers gain access to abandoned accounts

ID: 9720a598-b51e-50fa-9f1b-27353ff82d53

STIX ID: report--9720a598-b51e-50fa-9f1b-27353ff82d53

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-14

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

**Executive summary:** A flaw in Google’s OAuth "Sign in with Google" can allow attackers who register defunct startup domains to recreate former employee email accounts and access linked SaaS services (Slack, Notion, Zoom, HR systems), potentially exposing sensitive data; TruffleSecurity demonstrated the issue, Google awarded a bounty but the vulnerability remains unresolved.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.