Hacker News new | ask | show | jobs
by chii 23 days ago
The attack requires a third party to unknowingly click on the engineered URL that leak private video title. Not sure if it counts as a POC if you can only use your own channel to prove it works.

But still, it would require a user interaction to click on the link to leak data - and google should acknowledge it as an issue, because an attacker should never be able to generate a link they control in a trusted/secure environment.

1 comments

I understand the purported vulnerability. What I am saying is that I would be surprised if the URL were rendered, let alone made it to the victim.
I ended up making it render automatically, but they didn't really seem to care.
Wow, that's pretty wild. Updating your post with pictures would be cool.