OAuth Token Bypass Vulnerability in Google Play Services SDK
CVE-2014-7922
Currently unrated
Summary
A security flaw in the Google Play Services SDK allows malicious applications to exploit the GoogleAuthUtil.getToken method. By manipulating parameters in OAuth token requests via the Bundle extras, attackers can bypass consent dialogs, granting them unauthorized access to sensitive OAuth scopes, including the SID and LSID scopes. This exploitation could lead to unauthorized access to a user’s Google account and sensitive information.
References
Timeline
Vulnerability published
Vulnerability Reserved