OAuth Token Bypass Vulnerability in Google Play Services SDK
CVE-2014-7922

Currently unrated

Key Information:

Vendor
Google
Vendor
CVE Published:
23 February 2015

Summary

A security flaw in the Google Play Services SDK allows malicious applications to exploit the GoogleAuthUtil.getToken method. By manipulating parameters in OAuth token requests via the Bundle extras, attackers can bypass consent dialogs, granting them unauthorized access to sensitive OAuth scopes, including the SID and LSID scopes. This exploitation could lead to unauthorized access to a user’s Google account and sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.