top of page

Security Bulletin

Public·4 members

Google OAuth Vulnerability Exposes Millions via Failed Startup Domains



Who:

  • Vulnerability discovered in Google’s “Sign in with Google” OAuth authentication flow.

  • Truffle Security, led by co-founder and CEO Dylan Ayrey, identified the issue.

What:

  • Attackers can exploit domain ownership changes by purchasing domains of defunct startups.

  • Re-created email accounts on purchased domains can be used to access SaaS platforms previously tied to the accounts, such as OpenAI ChatGPT, Slack, Notion, Zoom, and HR systems.

  • Sensitive data at risk includes tax documents, pay stubs, Social Security numbers, and hiring records.

Impact:

  • Millions of users’ data could be compromised.

  • No current protections for downstream software providers against this flaw.

  • Google reopened the bug report (December 2024), awarded a bounty of $1,337, and labeled the issue as high impact.

  • Individuals remain vulnerable once off-boarded from startups, with no safeguards against domain ownership exploitation.

Read the full article HERE


11 Views
bottom of page