Collected research
Google Cloud Account Takeover via URL Parsing Confusion
Google's OAuth backend and Chrome disagree about URLs carrying two at-signs and IPv6 loopback literals, so a redirect target passes Google's loopback allow-list while the browser navigates to the attacker's host. An attacker can impersonate first-party clients such as the cloud CLI and collect the victim's grant for stealthy account takeover.
Record
- Researcher
- Mohamed Benchikh
- Published by
- Medium
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mohamed Benchikh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .