google-myaccount

1 article
sort: new top best
clear filter
0 5/10

Researcher bypassed CSP protection on Google MyAccount by URL-encoding a carriage return character in the origin parameter, enabling clickjacking attacks that could lead to account takeover. Google rewarded the finding with $7,500.

Google myaccount.google.com business.google.com Burp Suite Firefox ESR Firefox Quantum
apapedulimu.click · devanshbatham/Awesome-Bugbounty-Writeups · 6 hours ago · details