Web Hack List

Collected research

MB blog: Vulnerability in Hangouts Chat: from open redirect to code execution

Vulnerability in Hangouts Chat: from open redirect to code execution

The Hangouts Chat desktop client is an Electron app with no address bar, so redirecting its main window to an attacker domain leaves the user no way to tell. Chaining a chat.google.com/accounts redirect with a known open redirect on accounts.google.com loads an attacker-controlled login page inside the app window, giving highly credible phishing.

Record

Document
Vulnerability in Hangouts Chat: from open redirect to code execution
Published by
blog.bentkowski.info
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of blog.bentkowski.info, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .