A flaw in the Google OAuth system exposes millions of users via abandoned accounts


  • Buying domains from companies that are shutting down can provide access to their SaaS accounts, research shows
  • Google claims that it is not a vulnerability and that companies should ensure that they do not leave sensitive information behind
  • Researchers suggest additional safety measures

Experts have found a vulnerability in Google’s OAuth feature “Sign in with Google” that could allow malicious actors to access sensitive data belonging to businesses that have shut down.

Google acknowledged the bug but is not doing much to fix it, instead saying it’s up to companies to ensure the security of the data they leave behind.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top