google-docs

2 articles
sort: new top best
clear filter
0 6/10

Clickjacking vulnerability in Google Docs where the absence of X-Frame-Options headers allows embedding the service in iframes, enabling attackers to trick users into activating voice typing and recording private conversations via microphone permissions.

Google Docs Raushan Raj
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 5/10

Security researcher reports six clickjacking vulnerabilities across Google services (Play Store, Payments, Docs Picker, Sites) totaling $14,981.70, exploiting improper X-Frame-Options/CSP configurations and open redirects to enable unauthorized user actions like unintended subscription charges, account compromise, and private content exposure.

Google Play Google Payments Google Docs Picker Google Sites YouTube Raushan Raj
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details