beta-testing

1 article
sort: new top best
clear filter
0 8/10

Ryan Kovatch discovered two critical vulnerabilities in YouTube's Video Builder beta tool: the ability to upload unlisted videos to any YouTube channel by manipulating channel IDs in API requests, and a cryptographic key leakage via error messages revealing decryption key hashes. Both issues were reported, triaged as P1/S1 and P2/S2, and resulted in a $6,337 bounty.

YouTube Google Ryan Kovatch YouTube Video Builder Charles (debugging proxy) YouTube Studio
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details