NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / #BugAlert: Gmail bug allowed sending fake emails from real accounts
    Next Article
    #BugAlert: Gmail bug allowed sending fake emails from real accounts

    #BugAlert: Gmail bug allowed sending fake emails from real accounts

    By Shubham Sharma
    Aug 21, 2020
    05:16 pm

    What's the story

    Gmail has been having a really bad time lately.

    Just yesterday, the Google-owned service dealt with its second major outage in two months and drew flak from millions of users around the world.

    Now, a security researcher has revealed that it also carried a dangerous bug, one that opened a way for email spoofing.

    Here's all you need to know about it.

    Issue

    Bogus emails from real accounts

    Discovered by Allison Hussain, the issue tied to weakness in email routing rules and allowed sending bogus emails from legitimate Gmail addresses.

    This kind of attack could easily be used by cybercriminals to pose as a known person and trick an unsuspecting individual into a scam.

    For instance, they may send you a fake email asking for money using the address of your friend.

    Risk

    Bypassed major security standards

    Hussain found that the issue bypassed the advanced security protocols Google had implemented to prevent spoofing.

    Currently, Gmail uses Sender Policy Framework and Domain-based Message Authentication, Reporting, and Conformance to compare the sender's IP address to a pre-approved list of IPs from the domain's mail server.

    An email is successfully sent/received only when the IPs match, but here, the message skipped the checks altogether.

    Test

    Test confirmed the bypassing attack

    To test the bug, Hussain used her personal G Suite domain to send an email from a @google.com address to a G Suite email account on a domain she did not control.

    Normally, the message, from a different IP address, should have been stopped by the DMARC and SPF protocols, but the message went through without any hiccup and landed in the targeted mailbox.

    Fix

    Google deployed mitigations, only months after being informed

    Hussain discovered and reported the dangerous flaw in April, but Google remained silent.

    When the researcher contacted the company, it responded that the fix is due to be released in September.

    So, she decided to make the bug public, prompting Google to take action sooner than planned by deploying mitigations to prevent any email forgery attacks.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Gmail
    Security
    Google

    Latest

    Bangladesh Cricket Board pondering over Bangladesh's tour of Pakistan Bangladesh Cricket Board
    Why Virat Kohli's presence could lift India in England? Stats Virat Kohli
    Google Workspace accounts gain access to Gemini Live feature Google
    Adani Group deploys India's 1st hydrogen-powered truck in Chhattisgarh Adani Group

    Gmail

    Gmail for Android now lets you customize swipe actions Android
    Gmail for iOS gets AI-based high priority push notifications iOS
    Forget machines, even humans read your Gmail messages Technology
    Google's Move Mirror AI experiment matches your moves with photos Google

    Security

    Google sued for spying on students through Chromebooks: Details here WhatsApp
    Hackers are mysteriously stealing from PayPal accounts for online shopping PayPal
    New bug exposes Wi-Fi traffic of billion devices (including phones) Google
    Decathlon exposes data of millions of customers, employees Data Leak

    Google

    NewsBytes Briefing: Google sued for shady practices, and more Facebook
    Google Pixel 4a tipped to be launched on August 3 Ram (Random Access Memory)
    Big Tech CEOs to testify before Congress: All details here Facebook
    NewsBytes Briefing: Google extends work from home and more X
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025