Yet another Google vulnerability
Posted by multippt
This is seriously bad news for Google, especially with already 3 serious vulnerabilities in its system found in the space of 1 month. Yes, they may have been quick to patch it up within hours of it being reported, but this might show that the hackers are evolving.
This vulnerability is one of the few Google’s XSS vulnerabilities reported. It allows a person to gain unauthorized access to your Google account (includes GMail, Blogger, etc.). Now that is serious! And that is not all… this vulnerability allows the hacker to steal cookies that can be used to hijack your account, and this can be done by visiting a rigged website. Well, I guess you could use the phrase “No one’s going to steal my cookies!” (very bad pun unintended).
A possible precaution that not everyone wants to take to avoid the problem is to log off your account while viewing other websites.
Via zdnet (Don’t worry, they *probably* won’t steal your account)



