Google takes some user supplied data in a URL parameter which it expects to be a domain name, but does not validate it is a proper domain name or sanitise it. They then inject this value into the page inside an inline block of Javascript, controlling the next page you will visit (halfway […]

The post Hijack the Google Login flow (Bug Bounty Submission) appeared first on Tom Anthony.