GMail JS Security Flaw Exposes All Your Contacts


Tried to link to the original post but it seems to have gone AWOL, but Engadget does a nice job of explaining what's going on. Gmail bug exposes your mail account to spammers

Well, we hate to break the bad news at the dawn of the new year but there's a weakness in Gmail which exposes your email address to any web site capable of exploiting the bug. As reported on Digg, the exploit takes advantage of the fact that Google puts your details into a JS file. As a result, if you're logged into Gmail and browsing the web, any rogue website can declare the function "google" and then parse all your contacts.



I have tried it. Google still hasn't fixed it! No comment...

