New issue
Advanced search Search tips

Issue 784734 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 696286
Owner: ----
Closed: Nov 2017
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Steal Google account using account recovery process

Reported by meahmedt...@gmail.com, Nov 14 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36

Steps to reproduce the problem:
1. Enter the email address
2. I forgot the password
3. Entering an emergency email to verify it (not related to the hacker account)
4. Submit a support request
5. Grab the account

What is the expected behavior?
Google email hack and grab the entire account

What went wrong?
Hi Google
There is a serious security vulnerability that allows anyone to hack Google email easily in a few days from 3 days to just 5 days!
The account is taken up as soon as you know the date you created your Google Account
First, it bypasses all stages of the recovery of the account and the entry of Emile has nothing to do with the hacker account or as an account recovery
Then he sends a request to Google and the account is hacked in a few days
I have filmed the number 2 report
The first report bears the name:
It is Li's first penetration stages
The second report,
Which is the last step to enter the account after waiting several days and control the account fully refund from Google

Please review and watch the attached reports well and close this gap of the utmost importance because already this is very dangerous Anyone can know the date of creating any Google account by phone to the owner of the account and convince him anything says the date of creation !!
Please close this vulnerability and update your account recovery interface
Thanks Google

Did this work before? Yes 

Chrome version: 61.0.3163.100  Channel: n/a
OS Version: 6.3
Flash Version: 

Please update the password-forgetting interface for maximum importance after viewing these reports
 
Google Email in a few days.wmv
5.8 MB Download
Google email hack in few days (proof of hacking).wmv
2.2 MB Download
Mergedinto: 696286
Status: Duplicate (was: Unconfirmed)
Summary: Steal Google account using account recovery process (was: Google Email in a few days)
This does not represent a security vulnerability in Chrome.

Vulnerabilities in non-Chrome products can be reported to Google here: https://www.google.com/about/appsecurity/reward-program/index.html
Project Member

Comment 3 by sheriffbot@chromium.org, Feb 20 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
The error has already been closed
Thanks for following
What is the reward?

2018-02-20 7:20 GMT-08:00 sheriff… via monorail <
monorail+v2.4164592774@chromium.org>:

Sign in to add a comment