Security Hole Fixed in Google Reader

Google late Wednesday fixed a security flaw in its Google Reader RSS feed aggregation tool, which opened the door for a cross-site scripting attack. The vulnerability was disclosed in detail on Tuesday, and enabled an attacker to steal personal data from Google users.

"What are the implications of this attack for Google? Well, for starters, I can put a phishing site on Google. “Sign up for Google World Beta.” I can steal cookies to log in as the user in question, I can use the credentials of the user to screen scrape any of the content off of the www cname, including changing options like adding my RSS feed to your page, or deleting them," read a post on the ha.ckers.org blog.

3 Responses to Security Hole Fixed in Google Reader

Why Trust Us



At BetaNews.com, we don't just report the news: We live it. Our team of tech-savvy writers is dedicated to bringing you breaking news, in-depth analysis, and trustworthy reviews across the digital landscape.

BetaNews, your source for breaking tech news, reviews, and in-depth reporting since 1998.

© 1998-2025 BetaNews, Inc. All Rights Reserved. About Us - Privacy Policy - Cookie Policy - Sitemap.