A flaw in Google’s OAuth system is exposing millions of users through abandoned accounts


  • Buying domains from companies that go out of business could give them access to your SaaS accounts, research finds
  • Google argues that it is not a vulnerability and that companies should make sure they do not leave sensitive information behind.
  • Researchers propose additional safeguards

Experts have found a vulnerability in Google’s “Sign in with Google” OAuth feature that could allow malicious actors to access sensitive data belonging to companies that have gone out of business.

Google acknowledged the flaw, but isn’t doing much to fix it, rather saying it’s up to companies to ensure the security of the data they leave behind.

Leave a Comment

Your email address will not be published. Required fields are marked *