Close Menu
  • Home
  • UNSUBSCRIBE
  • News
  • Lifestyle
  • Tech
  • Entertainment
  • Sports
  • Travel
Facebook X (Twitter) WhatsApp
Trending
  • Can people catch infections from plants?
  • Andes virus spreads via ‘close contact’ — but what exactly does that mean?
  • 8-year-old African American boy from Colonial Maryland found buried with white Colonists, and it’s unclear if he was enslaved
  • Science news this week: PCOS has a new name, Neanderthals were the world’s oldest dentists, and the first nuclear bomb explosion spawned an ‘alien’ crystal
  • Newly discovered, blue-whale-size asteroid will fly super close to Earth Monday — and you can watch it live
  • Don Juan Pond: Antarctica’s salty, syrupy lake that never freezes, even when it’s minus 58 F
  • Withings ScanWatch 2 review: Style meets next-level health monitoring
  • AI Chatbots are turbo-charging violence against women and girls: We urgently need to regulate them | Yvonne McDermott Rees
Facebook X (Twitter) WhatsApp
Baynard Media
  • Home
  • UNSUBSCRIBE
  • News
  • Lifestyle
  • Tech
  • Entertainment
  • Sports
  • Travel
Baynard Media
Home»Tech»Google patched a major security flaw that could’ve exposed YouTubers’ email addresses
Tech

Google patched a major security flaw that could’ve exposed YouTubers’ email addresses

EditorBy EditorFebruary 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Google has fixed a security flaw that exposed the email addresses of YouTube users, a potentially massive privacy breach.

Google — which owns YouTube — has confirmed that the vulnerabilities discovered by cybersecurity researchers, who go by Brutecat and Nathan, have been addressed, according to a report in BleepingComputer.

Aside from the breach of privacy that would’ve affected all YouTube accounts, many YouTubers like controversial content creators, investigators, whistleblowers, and activists keep their identities anonymous to protect their safety. Exposing such users’ emails could have had huge ramifications.

SEE ALSO:

Google is reportedly developing a ‘fake’ email feature to help you avoid spam

Brutecat discovered that blocking a user on YouTube revealed a unique internal identifier Google uses for each user across all of its platforms (Gmail, Google Drive, etc.) called a Gaia ID. They then figured out that simply clicking the three dot icon of a user’s live chat profile to access the block function triggered an API request that revealed their Gaia ID.

Mashable Light Speed

This in itself is already a security flaw since it exposed the unique identifiers for YouTube accounts that is only meant to be used internally. But now that Brutecat was able to retrieve users’ Gaia IDs, they set out to see if they could reveal the email addresses associated with each ID.

With Nathan’s help, the two researchers surmised they could do this with “old forgotten Google products since they probably contained some bug or logic flaw to resolve a Gaia ID to an email.” Using Google’s Recorder app for Pixel devices, they tested sharing a recording with an obfuscated Gaia ID and blocked the user from receiving an email notification by renaming the file with a 2.5 million letter name, which broke the email notification system because it was too long.

Now that the hypothetical victim wouldn’t be notified, the researchers sent the file sharing request with the Gaia IDs, effectively converting the ID into an email address.

Thanks to Brutecat and Nathan’s sleuthing, Google was able to lock down that vulnerability and prevent hackers from accessing everyone’s email address associated with their YouTube accounts. The vulnerability was disclosed to Google in Sep. 2024 and was finally fixed on Feb. 9, 2025. That’s a long time for potential exposure, but Google confirmed to BleepingComputer that there were “no signs that any attacker actively exploited the flaws.”

In exchange for their work, the researchers received a cool $10,633. Phew, crisis averted.

Topics
Cybersecurity
YouTube



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTrump says he spoke to Putin about ending the war in Ukraine
Next Article Michael B. Jordan Shares Dating Life 2 Years After Lori Harvey Breakup
Editor
  • Website

Related Posts

Tech

iPhone exploit DarkSword has been released in the wild

March 24, 2026
Tech

The U.S. router ban: Everything you need to know

March 24, 2026
Tech

Underage sexual content, self-harm info targeted by OpenAI’s new open-source prompts

March 24, 2026
Add A Comment

Comments are closed.

Categories
  • Entertainment
  • Lifestyle
  • News
  • Sports
  • Tech
  • Travel
Recent Posts
  • Can people catch infections from plants?
  • Andes virus spreads via ‘close contact’ — but what exactly does that mean?
  • 8-year-old African American boy from Colonial Maryland found buried with white Colonists, and it’s unclear if he was enslaved
  • Science news this week: PCOS has a new name, Neanderthals were the world’s oldest dentists, and the first nuclear bomb explosion spawned an ‘alien’ crystal
  • Newly discovered, blue-whale-size asteroid will fly super close to Earth Monday — and you can watch it live
calendar
May 2026
M T W T F S S
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    
Recent Posts
  • Can people catch infections from plants?
  • Andes virus spreads via ‘close contact’ — but what exactly does that mean?
  • 8-year-old African American boy from Colonial Maryland found buried with white Colonists, and it’s unclear if he was enslaved
About

Welcome to Baynard Media, your trusted source for a diverse range of news and insights. We are committed to delivering timely, reliable, and thought-provoking content that keeps you informed
and inspired

Categories
  • Entertainment
  • Lifestyle
  • News
  • Sports
  • Tech
  • Travel
Facebook X (Twitter) Pinterest WhatsApp
  • Contact Us
  • About Us
  • Privacy Policy
  • Disclaimer
  • UNSUBSCRIBE
© 2026 copyrights reserved

Type above and press Enter to search. Press Esc to cancel.