[ad_1]
21 Apr 2023Ravie LakshmananCloud Security/Vulnerability
Cybersecurity researchers have revealed details of a now-fixed zero-day flaw in Google Cloud Platform (GCP) that could have allowed threat actors to hide an immovable malicious application within a victim’s Google account .
Dubbed GhostToken by Israeli cybersecurity startup Astrix Security, the flaw impacts all Google accounts, including enterprise-focused Workspace accounts. It was discovered and reported to Google on June 19, 2022. The company rolled out a global patch more than nine months later on April 7, 2023.
“Vulnerability […] allows attackers to gain permanent and unmovable access to a victim’s Google account by converting an already authorized third-party application into a malicious trojan app, leaving the victim’s personal data exposed forever,” Astrix said in a report .
Simply put, the flaw allows an attacker to hide their malicious app from the application management page of a victim’s Google Account, thus effectively preventing users from revoking access to it.
This is accomplished by deleting the GCP project associated with the authorized OAuth application, placing it in a “delete pending” state. The threat actor, armed with this ability, could then discover the rogue app by resetting the project and use the access token to obtain the victim’s data and make them invisible again.
“In other words, the attacker holds a ‘ghost’ token on the victim’s account,” Astrix said.
The type of data that can be accessed depends on the permissions granted to the app, which attackers can abuse to delete files from Google Drive, write emails on behalf of the victim to perform social engineering attacks, track locations, and exfiltrate data sensitive from Google Calendar, Photos and Drive.
“Victims can unknowingly authorize access to such malicious applications by installing an innocent-looking app from the Google Marketplace or one of the many productivity tools available online,” Astrix added.
NEXT WEBINAR
Zero Trust + Deception: Learn How To Outsmart Attackers!
Find out how Deception can detect advanced threats, stop lateral movement, and improve your Zero Trust strategy. Join our in-depth webinar!
Save my place!
“Once the malicious app has been whitelisted, an attacker who exploits the vulnerability can bypass Google’s ‘Apps with access to your account’ management feature, which is the only place Google users can view third-party apps linked to your account.”
Google’s patch addresses the issue by now displaying apps that are in a deletion pending state on the third-party login page, allowing users to revoke the permission granted to those apps.
The development comes as Google Cloud fixed a privilege escalation flaw in the Cloud Asset Inventory API dubbed Asset Key Thief that could be exploited to steal user-managed service account private keys and gain access to valuable data . The problem, discovered by SADA in early February, was fixed by the tech giant on March 14, 2023.
The findings come just over a month after cloud incident response firm Mitiga revealed that adversaries may be leveraging “insufficient” forensic visibility into GCP to exfiltrate sensitive data.
Did you find this article interesting? Follow us on Twitter and LinkedIn to read more of our exclusive content.
|
Sources 2/ https://thehackernews.com/2023/04/ghosttoken-flaw-could-let-attackers.html The mention sources can contact us to remove/changing this article |
[ad_2]