A researcher disclosed a Google identity provider vulnerability that allowed account takeover through the OAuth 2.0 Device Authorization Grant (RFC 8628). The issue reportedly stemmed from two flaws in Google's implementation: a device authorization session could be transferred across browsers using a copied challenge URL, and the authorization server did not ensure that the client_id and requested scopes in the later consent step matched those originally tied to the issued device_code. The write-up describes the bug as a confused deputy condition that let attackers hijack device-code sign-in flows and obtain tokens for arbitrary Google-registered clients.
By combining those weaknesses with prompt=none, an attacker could allegedly send a single link to a victim already signed in with Google and trigger silent token issuance without a consent screen, fresh 2FA challenge, or obvious account-activity warning. The researcher said the attack could move beyond limited scopes such as YouTube TV and be escalated to Google Cloud permissions and even Gmail access through IMAP XOAUTH2 when a substituted client was permitted to request https://mail.google.com. According to the disclosure, the bug was reported to Google through its VRP, initially rejected, later reopened, fixed, and ultimately awarded a $13,337 bounty.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
After the issue was reopened and remediated, the researcher received a $13,337 reward from Google. The bounty recognized the reported universal account-takeover vulnerability in Google's device authorization flow.
Google fixed the reported vulnerability affecting its identity provider implementation of the OAuth 2.0 device code flow. The flaw chain could enable one-click, invisible account takeover and escalation to broader Google scopes, including Google Cloud and Gmail access via IMAP XOAUTH2.
A researcher reported a chained account-takeover vulnerability in Google's OAuth 2.0 Device Authorization Grant implementation to the Google Vulnerability Reward Program. The issue involved transferable device-code sign-in sessions and missing binding between device_code, client_id, and scope, enabling silent token issuance for arbitrary clients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcereddit.com
Open sourcesecuritysenses.com
Open sourceweirdmachine64.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.