Google has fixed a security flaw that exposed the email addresses of YouTube users,free sex video hd a potentially massive privacy breach.
Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.
Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.
Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.
This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.
With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.
Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.
Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."
In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.
Topics Cybersecurity YouTube
Here's what we know about alleged NSA leaker Reality Leigh WinnerWhatsApp adds new photo sharing features and a quick reply shortcut'Planet of the Apps' combines several shows and strips them of excitementThe Cavs' locker room reportedly smelled like weed after NBA Finals Game 2First look: Apple's new 27Whoever came up with Popeyes new cookieTidal's latest '4:44' ads have birthed hilarious theories about JayiOS 11 will help you conserve precious iPhone storageOnePlus 5 might beat the iPhone 7 Plus by unapologetically copying itYour cracked iPhone screen might soon be easier and cheaper to repairAmazon to offer discounted Prime membership to lowChina debuts driverless train that only needs white painted lines as tracks'Stranger Things' Season 2 won't have a Barb resurrection, thank goodnessComic book that explores psychosis has no panelsComic book that explores psychosis has no panelsKudos to this dude who wore the same shirt in every school photo for 7 years'To Kill a Mockingbird' will soon get a graphic novel adaptationLyft partners with nuTonomy to bring selfKaty Perry can't find a signal on 'Witness'Nintendo's theme park is coming along nicely Cooking With Pather Panchali Early Cyber Monday 2023 laptop deals at Walmart: Save up to $551 'Bad Boys 2' is Michael Bay at his best, giving into his worst impulses Early Cyber Monday MacBook deals: M1, M2, and M3 at record lows How to verify your Tinder profile with video selfies Early Cyber Monday Fire TV deals 2023: Amazon's sale is live Best early Cyber Monday Apple AirTags deals in 2023 The Life and Times of the Literary Agent Georges Borchardt Lonesome Together by Drew Bratcher Staff Picks: Mermaids, Wrestlers, and Gawkers by The Paris Review America’s First Female Mapmaker by Ted Widmer Early Cyber Monday: Lego Ideas BTS Dynamite kit on sale for $64.99 at Amazon How to connect Spotify to BeReal Abridged Classics by John Atkinson Netflix is officially eliminating password sharing Notations by Mequitta Ahuja 'Love is Blind''s live reunion crashed Netflix. The internet reacted. Three Brief Encounters with Anthony Bourdain Who Gets to Be a Mad Scientist? My Own Boundaries Seem to Be Fading: An Interview with Lauren Groff
1.632s , 8613.1328125 kb
Copyright © 2025 Powered by 【free sex video hd】,Steady Information Network