Google has fixed a security flaw that exposed the email addresses of YouTube users,Goddess of female eroticism and sexuality Goddess of female eroticism and sexuality greek a potentially massive privacy breach.
Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.
Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.
Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.
This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.
With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.
Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.
Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."
In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.
Topics Cybersecurity YouTube
Facebook and Instagram told to overhaul nudity policies by Oversight BoardElizabeth Warren creatively calls out Facebook's problematic ad policyTrump's letter to Turkish president is so ridiculous people didn't believe it was realThis Italian translator can't believe her ears translating TrumpSamsung's new invention could usher in a very different foldable phone'Quordle' today: See each 'Quordle' answer and hints for January 22President Trump just literally begged us to impeach himKitty Forman is the best TV mom, and 'That '90s Show' proves why'Quordle' today: See each 'Quordle' answer and hints for January 19Researchers make ChatGPT generate malware codeWhy is it called a snow moon? (And when to see it)'Quordle' today: See each 'Quordle' answer and hints for January 19Rebekah Vardy vs Coleen Rooney drama is the greatest use of Instagram Stories everResearchers make ChatGPT generate malware codeResearchers make ChatGPT generate malware codeThis year's PSAT memes are here to anger the College BoardWatch Olympic divers flawlessly take on the 'Avengers' pool challenge'Fire Emblem Engage' reviewNetflix's password sharing crackdown is finally happening early 2023Want another great video game adaptation like 'The Last of Us'? Watch 'Arcane.' A strong solar storm may bring auroras to your backyard Wednesday South Park game's difficulty will be based on your skin color in a bold Equifax says stolen info could impact 143 million U.S. consumers Alexander Skarsgard trolls brother at 'It' premiere Listen to the 14 Hurricane Irma is being detected by earthquake 'Back' is the new British comedy every 'Peep Show' fan needs to watch If the iPhone 8 costs $1,200, feel free to blame Samsung Lyft and Drive.ai will bring self Game of Thrones: Who will kill Littlefinger in the books? Not Sansa. 'Black Mirror' has revealed two photos from Season 4, so start theorizing The 5 least terrible ghost hunting apps for your phone, reviewed The world's best airport has handed out smart glasses to ground staff Florida's nuclear plants prepare for the arrival of Hurricane Irma Irma devastated Barbuda but it didn't 'wipe the island off the map' 'Pokémon Go' bounces back after its disastrous Fest with a new lineup of events Adidas releases puke and beer repellent shoes ahead of Oktoberfest Sheriff tweets that anyone with a warrant seeking shelter from Hurricane Irma will be jailed Now even chocolate can be millennial pink, too $797 million in 3 months: Blockchain’s newest industry is going crazy
3.427s , 10197.3046875 kb
Copyright © 2025 Powered by 【Goddess of female eroticism and sexuality Goddess of female eroticism and sexuality greek】,Charm Information Network