【Brother in law Who Gave His Sister in law a Little Sex Education】
Google has fixed a security flaw that exposed the email addresses of YouTube users,Brother in law Who Gave His Sister in law a Little Sex Education a potentially massive privacy breach.
Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.
Aside from the breach of privacy that would've affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users' emails could have had huge ramifications.
You May Also Like
SEE ALSO: Google is reportedly developing a ‘fake’ email feature to help you avoid spam
Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user's live chat profile to access the block function triggered an API request that revealed their Gaia ID.
This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users' Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.
With Nathan's help, the two researchers surmised they could do this with "old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email." Using Google's Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.
Now that the hypothetical victim wouldn't be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.
Related Stories
- Apple Maps follows Google, relabels Gulf of Mexico as America
- Google: We're not participating in European fact-checking rules for Search or YouTube
- YouTuber GamersNexus sues Honey over alleged scam
Thanks to Brutecat and Nathan's sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone's email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That's a long time for potential exposure, but Google confirmed to BleepingComputer that there were "no signs that any attacker actively exploited the flaws."
In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.
Topics Cybersecurity YouTube
Search
Categories
Latest Posts
Amazon CEO tries to sell kids on working on the moon
2025-06-27 02:45The internet is fact
2025-06-27 02:37Guy becomes 'best friends' with a kookaburra after giving it CPR
2025-06-27 01:35Samsung's 108
2025-06-27 01:32Trump praises storm response as historic disaster unfolds in Houston
2025-06-27 00:58Popular Posts
'Friends' hits theaters for 25th anniversary celebration
2025-06-27 03:18Lady Gaga responds to recent shootings with classroom philanthropy
2025-06-27 01:07Facebook is working on a dark mode version of its Android app
2025-06-27 01:05Report: Match Group dating apps conceal assault cases
2025-06-27 01:03Featured Posts
Even Trump's Earth Day message was anti
2025-06-27 03:14Kaspersky Lab exposed users' browsers to website tracking
2025-06-27 02:14Facebook reminds private groups: We're watching
2025-06-27 02:01Use Your Gaming Laptop and Play On Battery Power? Is It Possible?
2025-06-27 01:35Popular Articles
Use Your Gaming Laptop and Play On Battery Power? Is It Possible?
2025-06-27 03:04Uber Pool without all the stops is finally an option for some rides
2025-06-27 01:48Pumpkin Spice Lattes may be back at Starbucks earlier than ever
2025-06-27 01:31Hackers can ransomware your fancy digital camera
2025-06-27 01:26Miami Heat vs. Brooklyn Nets 2025 livestream: Watch NBA online
2025-06-27 01:12Newsletter
Subscribe to our newsletter for the latest updates.
Comments (5635)
Unique Information Network
Here's how I feel about all this Stephen Hawking 'news' going around
2025-06-27 02:42Culture Information Network
A sonic cyberattack could cause speakers to play dangerous sounds
2025-06-27 02:20Palm Information Network
China claimed its troops can reach New Delhi in 48 hours and everyone cracked the same joke
2025-06-27 02:09Ignition Information Network
A sonic cyberattack could cause speakers to play dangerous sounds
2025-06-27 00:56Unobstructed Information Network
SpaceX will try to achieve 2 impressive feats on Monday
2025-06-27 00:50