TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
YouTube Cracks Down on Formulaic Videos in New Monetisation Update
Meta Prepares Chatbots That Ping You Unprompted and Recall Old Chats
Fresh iPhone, iPad, and Mac Art Arrives for New Umeda Apple Store
Why Apple Should Focus on the Foldable iPhone Instead of an iPad Fold
Why Apple’s Developer Cloud Dream Stalled—And Could Return
Saturday, Jul 5, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Hackers Breach Google Accounts Security, Bypassing passwords
The Tech Basic > News > New Security Vulnerability Allows Hackers to Access Google Accounts Without Passwords
News

New Security Vulnerability Allows Hackers to Access Google Accounts Without Passwords

Evelyn Blake
Last updated: 15 January 2024 19:09
Evelyn Blake
Share
SHARE

Security experts from CloudSEK have uncovered a novel security loophole. It enables hackers to gain unauthorized access to users’ Google accounts without the need to crack their passwords.

Contents
Exploiting Third-Party Cookies for Unauthorized AccessGoogle’s Response and Chrome Developers’ StatementRecommended Action to Prevent Google Accounts

Please follow us on Twitter and Facebook

The vulnerability was first disclosed on a Telegram channel on October 20, 2023. Cybersecurity professionals later incorporated it into a hacking tool called Lumma Infostealer.

Exploiting Third-Party Cookies for Unauthorized Access

The malware leverages third-party cookies to achieve unauthorized access to user data. Hackers can maintain continuous access to the user’s Google account even if the user changes the password.

The issue lies in Google’s authentication cookies, which facilitate convenient login across various platforms without the need to repeatedly enter credentials. Unfortunately, cybercriminals can collect these cookies through this method, bypassing Two-Factor Authentication (2FA) protection.

Hackers Breach Google Accounts Security, Bypassing passwords (1)

Google’s Response and Chrome Developers’ Statement

Google is actively addressing the problem, with Chrome developers, the most widely used browser, stating in a release that “Google has taken measures to secure any compromised accounts that are detected.”

Read Also: Bluetooth’s Security Risk: Remote Control Vulnerability Leaves Android, iOS, And More Devices Exposed

Recommended Action to Prevent Google Accounts

Both Google and CloudSEK recommend a crucial step to mitigate potential issues: “resetting” these credentials. “If you suspect your account may be compromised, or as a general precaution, log out of all profiles in the browser to invalidate current session tokens.”

They further advise, “Next, change your password and log back in to generate new tokens. Changing the password locks out unauthorized access by invalidating the old tokens upon which data thieves depend, providing a crucial barrier to the continued functionality of the exploit”.

Read Also:

Understanding WhatsApp’s Secret Code: New Security Feature Protecting And Hiding Your Most Private Chats

TAGGED:Google
Share This Article
Facebook Reddit Copy Link Print
Share
Evelyn Blake
By Evelyn Blake
Follow:
Evelyn Blake is an investor in technology and journalist who has been in the nascent space since 2014. Her love and passion for technological innovations made her delve deeper into the world of technology evolution. As a journalist, Evelyn has been covering latest trends and emerging gadgetries. She is a philanthropist and human rights activist.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

YouTube

YouTube Cracks Down on Formulaic Videos in New Monetisation Update

Salman Akhtar
Meta Chatbots

Meta Prepares Chatbots That Ping You Unprompted and Recall Old Chats

Salman Akhtar
Umeda Apple Store

Fresh iPhone, iPad, and Mac Art Arrives for New Umeda Apple Store

Salman Akhtar
Apple

Why Apple Should Focus on the Foldable iPhone Instead of an iPad Fold

Salman Akhtar

You Might Also Like

Veo 3
News

How Veo 3 Could Unlock AI‑Driven Virtual Environments

Apple Watch
News

Google Keep leaves Apple Watch users without quick notes

YouTube
News

YouTube Raises Livestream Age to 16: New 2025 Rules

DeepSeek
News

German Privacy Watchdog Forces Apple and Google to Drop DeepSeek

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
Why Apple’s Developer Cloud Dream Stalled—And Could Return
Perfect Dark and Everwild Canceled in Microsoft’s Studio Purge
Apple Rolls Out Safari Technology Preview 222 with Key Bug Fixes
OpenAI Condemns Robinhood Tokens: Unauthorized “Equity”
WhatsApp Ad Integration Marks Meta’s Next AI Ad Push

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?