Gmail Security Bug Allows You To Spoof Your Email Address

Discussion in 'Android News' started by DroidModderX, Nov 16, 2015.

  1. DroidModderX

    DroidModderX Super Moderator
    Staff Member Premium Member

    Joined:
    Oct 6, 2011
    Messages:
    5,573
    Likes Received:
    2,086
    Trophy Points:
    478
    Ratings:
    +2,205
    [​IMG]

    Here is a troubling new bug only found in the Gmail Android app. Utilizing a bug in the Gmail app you can go to your account settings and change the display name. Your actual email address will then be hidden and the email recipient won't be able to see it. Simply add double quotation marks before and single quotations after the name you wish to be displayed.

    The double quotation marks trigger a parsing bug in the app. Independent security researcher Yan Zhu reported the bug to Google who returned the email stating that this was not a security vulnerability. The bug is a low risk security concern since it is only on the Android app, but could still lead to phishing attacks.

    via Motherboard
     
  2. Mustang02

    Mustang02 Diamond Member

    Joined:
    Aug 8, 2010
    Messages:
    7,625
    Likes Received:
    5,115
    Trophy Points:
    1,563
    Location:
    Ohio
    Ratings:
    +6,073
    Current Phone Model:
    Nexus 6P/5X
    Oh I'm going to mess with my friends.
     
    • Like Like x 1
    • Funny Funny x 1
    • Winner Winner x 1
  3. Mustang02

    Mustang02 Diamond Member

    Joined:
    Aug 8, 2010
    Messages:
    7,625
    Likes Received:
    5,115
    Trophy Points:
    1,563
    Location:
    Ohio
    Ratings:
    +6,073
    Current Phone Model:
    Nexus 6P/5X
    I received a GMAIL update today. I can't get this to work. Google may have patched it.
     
    • Like Like x 1