Comment on Google OAuth secrets exposed as account-hijacking MultiLogin vulnerability discovered
AliasAKA@lemmy.world 10 months ago
MultiLogin is a Chromium feature that can be abused to compromise a user’s Google account. The “bug” was unveiled by a malware developer known as PRISMA in October 2023. The cyber-criminal shared details about a critical exploit designed to generate persistent cookies for “continuous” access to Google services, even after a user’s password reset.
Oof. Another good reason to use Firefox I guess?
Eggyhead@kbin.social 10 months ago
Just to add a little more weight to your point.