Google Inc. has quietly patched a potentially dangerous security flaw in two of its business-facing services after a private security research outfit warned that malicious hackers could exploit the bug to hijack sensitive user information.The vulnerability was flagged—and fixed—in the Google AdWords and Google Services subdomains.Because both sites use data from the
Google Accounts username/password system, security experts said the flaw presented a major identity theft risk.
The bug was reported to Google by Israeli IT security services firm Finjan Software Ltd. on Sept. 22. Two days later, Google corrected the flaw and made it clear that no user data was compromised.
"[We were] alerted to this issue a little while ago and we worked quickly to fix the problem, which has now been resolved. No user data was compromised and we applaud Finjan for following industry best practices for vulnerability disclosure," a Google spokesperson said in a statement.
more ...