We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Google plugs hole exposing Gmail mail-boxes

Several users had email accounts hijacked



Google has fixed a security flaw in its Gmail web-based email service that allowed attackers to hijack users' email accounts.

"Google was recently alerted to a potential security vulnerability affecting the Gmail service. We have since fixed this vulnerability, and all current and future Gmail users are protected," Google spokesman Nathan Tyler said.

Tyler declined to discuss the nature of the problem, but a source close to Google confirmed that the flaw allowed an attacker to gain complete control over a user's account.

The problem was in the way Gmail authenticated users. An attacker could steal a so-called cookie file identifying the user by making use of a seemingly innocent link to Google's own website, according to a report on the website of the Israeli publication Nana NetLife Magazine on Thursday.

The cookie allowed an attacker to sign on to Gmail as the victim from any computer without having to enter a password. The attacker would continue to be able to access the Gmail account even if the password were changed, according to Nana NetLife, which cited an Israeli hacker named Nir Goldshlagger.

An investigation by Google found that only a handful of Gmail users were victimised, the source said.

Google announced Gmail in April, grabbing headlines because of the massive 1GB storage space provided with a Gmail account. The service is still officially in beta testing and internet users can only get accounts after receiving an invitation from a current user. Google does not disclose how many Gmail accounts it hosts.


IDG UK Sites

Samsung Galaxy Note 4 review: Great if you like big, expensive phones

IDG UK Sites

Why Sony's PS4 2.0 update is every gamer's dream (well, mine at least)

IDG UK Sites

This Grolsch ad combines stop-motion & CG for majestic results

IDG UK Sites

Apple rumours and predictions for 2015: What to expect from Apple in 2015