vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

Google device grants lost client and permission binding

A researcher reports USD 13,337 for a device-grant authorization-boundary failure.

Read the primary source IDAuthentication and identityReviewed 2026-10-03

Root cause

The account completing authentication could authorize a different requesting device, while client identity and permissions were not preserved through the grant. The researcher reasoned about consistency between initial authorization and final token authority. Cross-device sign-in alone is expected behavior; the reported failure was loss of the intended recipient and permission binding.

Demonstrated impact

The author reports third-party account access, elevated permissions and mailbox access. Reduced-interaction behavior required a signed-in user opening a link and relevant prior consent. Universal reach, unrestricted persistence and uniform absence of alerts are not independently established.

Lessons for review

  • Editorial lesson: preserve one server-side authorization decision across device identity, client identity, subject and permitted actions; every completion path must respect it.
  • The researcher recommends server-side grant binding and explicit device confirmation. These are proposed controls, not verified descriptions of the deployed fix.

Award and evidence

USD 13,337Bug Bounty · Researcher Reported

One chain award, counted once. The researcher uses $. USD is inferred from Google’s March 2017 program-wide denomination statement, about nine years before the April 2026 award. That context does not independently establish this individual award’s currency or settlement; cash receipt is unverified.

Fresh-read the primary narrative and award timeline with the older vendor currency context; explicitly qualified the temporal gap and inference. No testing.

  • No independently reviewed vendor evidence establishes technical reach, award or settlement.
  • The March 28, 2026 marked-fixed status does not establish deployment timing or patch contents.
  • Specific client permissions, existing consent and downstream token acceptance constrain the reported impact; one broad title does not prove every integration was affected.

Recorded timeline

Published
2026-07-15explicit
Reported
2026-02-25explicit
Awarded
2026-04-02explicit

Sources and provenance

  1. Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking weirdmachine64 · reviewed 2026-10-03
  2. VRP news from Nullcon Google Security Blog · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software