Collected research
MB blog: Vulnerability in Hangouts Chat: from open redirect to code execution
Vulnerability in Hangouts Chat: from open redirect to code execution
The Hangouts Chat desktop client is an Electron app with no address bar, so redirecting its main window to an attacker domain leaves the user no way to tell. Chaining a chat.google.com/accounts redirect with a known open redirect on accounts.google.com loads an attacker-controlled login page inside the app window, giving highly credible phishing.
Record
- Document
- Vulnerability in Hangouts Chat: from open redirect to code execution
- Published by
- blog.bentkowski.info
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of blog.bentkowski.info, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .