Root cause
Ordinary sensitive-field checks appeared effective, but an alternate metadata path exposed a cross-service association. The researcher then questioned whether monetized creator accounts inherited rights intended for specialist rights-management accounts.
Demonstrated impact
The demonstrated disclosure concerned the email stored when the target channel became monetized, which may differ from its current email. Broader phishing consequences were potential impact, not demonstrated account compromise.
Lessons for review
- Editorial lesson: check privacy guarantees across alternate response paths and linked services.
- Editorial lesson: separate caller eligibility for an API from authority over each returned object.
Award and evidence
USD 13,337 initial award plus USD 6,663 adjustment for this same report; awarded date records the final adjustment.
Fresh read of the primary researcher article through web text extraction; compared prerequisites, authorization boundary, demonstrated impact and remediation chronology with the existing record. No target testing or exploit reproduction.
- Award is reported by the cited source; cash settlement is not independently audited.
- The article does not supply implementation-level patch details or establish actual deployment timing.
Recorded timeline
- Published
- 2025-03-13explicit
- Public Disclosure
- 2025-03-13explicit
- Reported
- 2024-12-12explicit
- Awarded
- 2025-01-23explicit
Sources and provenance
- Disclosing YouTube Creator Emails for a $20k Bounty Arvin Shivram (Brutecat) · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.