Google OAuth Flaw Exposes Millions of Users Through Abandoned Accounts


  • Purchasing domains from companies that have gone out of business could give access to their SaaS accounts, study finds
  • Google says this is not a vulnerability and that companies need to make sure they don’t leave sensitive information behind.
  • Researchers offer additional guarantees

Experts have discovered a vulnerability in Google’s “Sign in with Google” OAuth feature that could allow bad actors to access sensitive data belonging to companies that have gone out of business.

Google has acknowledged the flaw, but is doing little to address it, instead saying it’s up to companies to ensure the security of the data they leave behind.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top