"Malware Exploits Google OAuth to Hijack Accounts and Steal Information"

1 min read
Source: 9to5Google
"Malware Exploits Google OAuth to Hijack Accounts and Steal Information"
Photo: 9to5Google
TL;DR

A new malware exploits a vulnerability in Google Chrome to steal session tokens and create persistent cookies, allowing attackers to access Google Accounts even after password changes. Google has responded by securing compromised accounts and clarifying that users can invalidate stolen sessions by signing out. The company recommends users to remove any malware, turn on Enhanced Safe Browsing, and avoid installing unfamiliar software. Despite Google's countermeasures, multiple malware groups claim to have adapted to these defenses.

Share this article

Want the full story? Read the original reporting

Read on 9to5Google