Google fixed a “high impact” security bug in Gmail’s password reset system that could have left any account wide open.
It was possible to exploit the flaw by sending a spoofed email that reminds the Gmail user that it’s time to reset their password. Security researcher Oren Hafif discovered the vulnerability.
RELATED STORIES
New Exploit Kit using TOR
AutoCAD Malware Lurking
Despite Arrest, RAT Usage Grows
Global Effort to Bring Botnet Down
Clicking on the link sends the user to a website that appears to look like a Google page and asks the user for a new password. That hacker-controlled site also initiates a cross-site request forgery attack via XSS that tricks Google into handing over the victim’s login cookie.
“I want you to be honest and agree that if Google says that ‘you’ve confirmed ownership’ of your Google Account, and asks you to choose a new password you will not do so? At least your auntie would!” Hafif said in a blog post explaining the attack.
The spoof site can shift the user to a secure Google web page, but by this point, the attacker will have harvested the username, new password and the login cookie for the account. Once inside, they would also get free rein to change passwords on other services associated with that Gmail email address.
Hafif said he alerted Google to the issue and the company fixed it within 10 days and confirmed he will receive a payment under its bug bounty program, although Google isn’t saying how much it is giving him.

