Google has fixed a security flaw that exposed the email addresses of YouTube users,julia stiles sex video a potentially massive privacy breach.
Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.
Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.
Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.
This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.
With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.
Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.
Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."
In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.
Topics Cybersecurity YouTube
Rigas FS vs. Galatasaray 2024 livestream: Watch Europa League for freeBill Nye is only taking selfies with climateArkadium mini crossword answers for October 2Elon Musk's X fined over $400,000 for refusing to address child abuse concernsTwente vs. Fenerbahce 2024 livestream: Watch Europa League for freeMicrosoft's latest Windows update is causing issues for some gamersLille vs. Real Madrid 2024 livestream: Watch Champions League for free'The Platform 2' review: A lesson in how to make a sciBest earbuds deal: Get a pair of Bose Ultra Open Earbuds for $249 at AmazonBest free AI coursesBill Nye is only taking selfies with climateBest outdoor deals: Save on outdoor gear ahead of Oct. Prime DayArkadium mini crossword answers for October 3Get two free Kindle books in October with Amazon First ReadsTesla recalls cybertrucks for dangerous rearview image issueTikTok could pull music from Phoebe Bridgers, Mitski, and Nirvana from the platformArkadium mini crossword answers for October 4Today's Hurdle hints and answers for October 4Best holiday deal: Save 20% on Lego Advent calendarsNYT Strands hints, answers for October 4 Australian man found not guilty of murdering his Tinder date Facebook might launch a cryptocurrency in the first half of 2019 Lady Gaga and Mark Ronson clap back at Patrick Carney's trash talk Google won't run political ads during Canada's election cycle Ivanka Trump speaks out about her father's remarks toward women 'Leaving Neverland' made me see the truth about Michael Jackson Queen Cersei gives her verdict on the debate with one resounding tweet The internet goes wild after Trump's 'If I win' pledge Past interview includes Trump praising 'nasty woman' Hillary Clinton Clinton calls out Trump for being a sore loser about the Emmys Ethereum's Constantinople upgrade goes as planned Trump called Clinton a 'nasty woman' in the debate's closing minutes NASA's deep sea drone Orpheus has plans to one day go to space J.K. Rowling delivers magical takedown of Donald Trump with a single tweet Poor Brian Williams can't quite say WikiLeaks Stressed out after the debates? You're not the only one We aren't collecting data about women and it's literally putting their lives at risk Facebook plans 'enterprise edition' of VR headsets I'm giving up podcasts to save my brain and soul from overload Fearless tiny dogs scare away huge bear from their yard
2.1129s , 10522.46875 kb
Copyright © 2025 Powered by 【julia stiles sex video】,Pursuit Information Network