On April 7, Google patched the GhostToken GCP vulnerability that could have allowed attackers to backdoor Google accounts using malicious OAuth applications
Google has addressed a Cloud Platform (GCP) security vulnerability impacting all users and allowing attackers to backdoor …
The team @AstrixSecurity disclosed a 0-Day flaw in GCP today called GhostToken 👻 Allowed malicious apps to be made invisible & unremovable in the Google Account console essentially allowing unlimited access ❌Disclosed June 2022 ✅Fixed April 2023 https://astrix.security/...