【eroticism studio 54】
Google has fixed a security flaw that exposed the email addresses of YouTube users,eroticism studio 54 a potentially massive privacy breach.
Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.
Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.
You May Also Like
SEE ALSO: Google is reportedly developing a ‘fake’ email feature to help you avoid spam
Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.
This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.
With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.
Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.
Related Stories
- Apple Maps follows Google, relabels Gulf of Mexico as America
- Google: We're not participating in European fact-checking rules for Search or YouTube
- YouTuber GamersNexus sues Honey over alleged scam
Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."
In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.
Topics Cybersecurity YouTube
Search
Categories
Latest Posts
Best free ChatGPT courses
2025-06-27 09:12NYT Strands hints, answers for March 11
2025-06-27 08:10Bluesky wants us to imagine a 'world without Caesars'
2025-06-27 07:38Amazon Kindle Paperwhite Kids: $139.99 at Amazon
2025-06-27 06:46Popular Posts
Preorder the new Anker Soundcore Sleep A30 earbuds with ANC for $159
2025-06-27 09:10Apple MacBook Air M3 deal: Save $300 at Amazon
2025-06-27 08:52NYT mini crossword answers for March 11, 2025
2025-06-27 08:09Best laptop deal: Get an M2 MacBook Air for $699 at Best Buy
2025-06-27 07:22Featured Posts
CES 2025: 7 AI
2025-06-27 09:00'The White Lotus' Season 3 finally reveals why Rick's in Thailand
2025-06-27 08:03Today's Hurdle hints and answers for March 11, 2025
2025-06-27 07:57Popular Articles
Best Aeropostale gift card deal: Save $7.50 at Amazon
2025-06-27 08:58Best Garmin deal: Save $39 on Forerunner 55 at Best Buy
2025-06-27 08:57Best eSIM for Ireland 2025
2025-06-27 08:27Nishioka vs. Alcaraz 2025 livestream: Watch Australian Open for free
2025-06-27 08:11Newsletter
Subscribe to our newsletter for the latest updates.
Comments (361)
Charm Information Network
Best AirPods deal: Apple AirPods 4 for $99.99 at Amazon
2025-06-27 08:38Exciting Information Network
Wordle today: The answer and hints for March 11, 2025
2025-06-27 07:43Information Information Network
NYT Connections hints and answers for March 9: Tips to solve 'Connections' #637.
2025-06-27 07:39Reality Information Network
Lille vs. Dortmund 2025 livestream: Watch Champions League for free
2025-06-27 07:11Highlight Information Network
The 12 Best Games on the iPhone
2025-06-27 06:47