Root cause
The account completing authentication could authorize a different requesting device, while client identity and permissions were not preserved through the grant. The researcher reasoned about consistency between initial authorization and final token authority. Cross-device sign-in alone is expected behavior; the reported failure was loss of the intended recipient and permission binding.
Demonstrated impact
The author reports third-party account access, elevated permissions and mailbox access. Reduced-interaction behavior required a signed-in user opening a link and relevant prior consent. Universal reach, unrestricted persistence and uniform absence of alerts are not independently established.
Lessons for review
- Editorial lesson: preserve one server-side authorization decision across device identity, client identity, subject and permitted actions; every completion path must respect it.
- The researcher recommends server-side grant binding and explicit device confirmation. These are proposed controls, not verified descriptions of the deployed fix.
Award and evidence
One chain award, counted once. The researcher uses $. USD is inferred from Google’s March 2017 program-wide denomination statement, about nine years before the April 2026 award. That context does not independently establish this individual award’s currency or settlement; cash receipt is unverified.
Fresh-read the primary narrative and award timeline with the older vendor currency context; explicitly qualified the temporal gap and inference. No testing.
- No independently reviewed vendor evidence establishes technical reach, award or settlement.
- The March 28, 2026 marked-fixed status does not establish deployment timing or patch contents.
- Specific client permissions, existing consent and downstream token acceptance constrain the reported impact; one broad title does not prove every integration was affected.
Recorded timeline
- Published
- 2026-07-15explicit
- Reported
- 2026-02-25explicit
- Awarded
- 2026-04-02explicit
Sources and provenance
- Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking weirdmachine64 · reviewed 2026-10-03
- VRP news from Nullcon Google Security Blog · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.