He found a way to Hijack Private Google Docs Screenshots with a clever hack - Google paid him $4000

Published: Jan. 24, 2021, 6:42 p.m.

A vulnerability in Google Feedback component in postMessage allowed this security researcher to find a way to hijack private screenshots   https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/ https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage

--- Send in a voice message: https://anchor.fm/hnasr/message