Google has fixed a security flaw that exposed the email addresses of YouTube users,sex hd video a potentially massive privacy breach.
Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.
Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.
Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.
This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.
With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.
Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.
Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."
In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.
Topics Cybersecurity YouTube
These 2017 'polar bear plunge' pics will give you chillsHere's your first peek at Lenovo's lowGoogle rolls out carrier billing option to Vodafone, Airtel subscribersMariah Carey rep claims she was 'set up to fail' at New Year's Eve performanceSeeing the start of 2017 through Spectacles is so 2017SpaceX reveals cause of September explosionIf you're in China, this Friday is the best day to purchase a Mac or iPhoneTurns out Benedict Cumberbatch has an IRL connection to Sherlock HolmesYou can now sell your old products on Amazon IndiaWhat kind of Snapchatter are you?The scary moment a car carrying backpackers' stuff falls off ferry and drifts out to seaBillie Lourd posts touching Instagram tribute to Carrie Fisher and Debbie ReynoldsCoachella 2017 lineup features Beyoncé, Radiohead and...Hans Zimmer?Ed Sheeran posts yet another cryptic clue, sends Twitter into meltdownPeople are 'theftThis dastardly college basketball trick play is an allVolvo wants you to never miss a meeting again. Thanks so much, reallyPSA: You can lawfully refuse to pay service charge at restaurants, hotels in this countrySamsung to reveal this month why the Galaxy Note7 kept explodingWhat kind of Snapchatter are you? Redux: A Good Reading Night by The Paris Review Redux: Without Wanting to Live Forever by The Paris Review Metadata on U.S. government memos reveals authors linked to Project 2025 Why is the internet crazy for the Rabbit R1? Watching 'True Detective: Night Country'? Chase it with this 'X The Voice of ACT UP Culture by Sarah Schulman The Covering Cherub: An Interview with Joshua Cohen by Martin Riker 'True Detective' Season 4, episode 1: Burning questions explored Classic Literature as Fortune Cookie Fortunes by Jean Redux: Mother for Whom the Whole Sky by The Paris Review OpenAI GPT Store users break rules with 'girlfriend' bots The 'Mean Girls' directors break down how social media shaped their movie musical Cooking with C. L. R. James by Valerie Stivers Cooking with Sigrid Undset by Valerie Stivers Why are people leaving Substack? YouTube will be slower if you're using an ad blocker A Continuous Musical Delight by Vijay Seshadri Artifact news app is shutting down, one year post Staff Picks: Jungles, Journeys, and Jealousy by The Paris Review America’s Dead Souls by Molly McGhee
3.0353s , 8611.8046875 kb
Copyright © 2025 Powered by 【sex hd video】,Evergreen Information Network