Google Fixes Serious Security Bug Impacting Gmail, G Suite Users Months After Its Discovery

Google engineers fixed the bug within seven hours after it was ultimately made public.

Advertisement
By Jagmeet Singh | Updated: 21 August 2020 14:04 IST
Highlights
  • Google was informed about the bug on April 3
  • Security researcher Allison Husain made the bug public on Wednesday
  • Gmail and G Suite services were both vulnerable due to the bug
Google Fixes Serious Security Bug Impacting Gmail, G Suite Users Months After Its Discovery

Gmail and G Suite users could be impacted by the bug that was discovered on April 1

Google has patched a security bug that was impacting both Gmail and G Suite email servers. The issue was identified and reported to Google in April, though the search giant took over four months in mitigation and ultimately released a patch on Wednesday. According to the security researcher who discovered the bug on April 1, it could have allowed hackers to send spoofed emails on behalf of any Gmail or G Suite users. The bug was also found to overcome Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting and Conformance (DMARC) rules while sending spoofed emails.

Security researcher Allison Husain publicly disclosed the bug impacting Gmail and G Suite email servers through a blog post on Wednesday that included a proof-of-concept (PoC). Husain said that although Google was planning to bring a fix sometime in September, it decided to patch the flaw within seven hours after it was made public. Google itself imposes a strict 90-day disclosure deadline for its bug-finding Project Zero initiative, publishing details about a bug at the end of the period regardless of whether the company has a fix for the issue — something Microsoft has learnt the hard way on several occasions.

As per Husain, the bug that was reported to Google on April 3 wasn't identical to the classic email spoofing that can easily be blocked by email servers using SPF and DMARC standards. “This issue is a bug unique to Google which allows an attacker to send mail as any other user or G Suite customer while still passing even the most restrictive SPF and DMARC rules,” said Husain.

The security researcher found that Google's backend structure for enabling Gmail and G Suite services could allow an attacker to redirect incoming emails and spoof the identity of any user using a native feature called “Change envelope recipient.” Husain also found that once exploited, the bug could send spoofed emails to an email gateway on Gmail and G Suite using custom mail routing rules and by overcoming the traditional SPF and DMARC checks.

Advertisement

“By chaining together both the broken recipient validation in G Suite's mail validation rules and an inbound gateway, I was able to cause Google's backend to resend mail for any domain which was clearly spoofed when it was received,” said Husain. “This is advantageous for an attacker if the victim they intend to impersonate also uses Gmail or G Suite because it means the message sent by Google's backend will pass both SPF and DMARC as their domain will, by nature of using G Suite, be configured to allow Google's backend to send mail from their domain.”

Husain added that since the spoofed emails were originating from Google's backend, they weren't likely to be caught by regular spam filters.

Advertisement

It is important to note that Google has deployed the patch at the server side, as noted by Catalin Cimpanu of ZDNet. Thus, users on Gmail and G Suite aren't required to make any changes from their end.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Gmail, G Suite, Google, email spoofing
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A26 Review
  2. Honor Pad 10 With Snapdragon 7 Gen 3 SoC, 10,100mAh Battery Launched
  3. Noise Buds F1 With Up to 50-Hour Playback Time Debuts at This Price Tag
  4. Xiaomi 15S Pro With With In-House XRING 01 SoC, 6,100mAh Battery Launched
  5. Lava Bold N1, Lava Bold N1 Pro India Pricing, Specifications Teased
  6. Vijay Sales Apple Days Sale Brings Discounts on These iPhone, Mac Models
  7. Xiaomi Pad 7 Ultra With XRING 01 SoC and 12,000mAh Battery Launched
  8. Samsung Tri-Fold Smartphone Price Leaked, Might Launch in Q3 2025
  9. iQOO Neo 10: From Display, Camera to Battery, Eveything We Know About It
  10. Xiaomi Civi 5 Pro With Snapdragon 8s Gen 4 SoC, 6,00mAh Battery Launched
  1. Trump Threatens 25 Percent Tariffs on Apple If iPhones Not Made in US
  2. iPhone 16 Pro Max, iPhone 15, MacBook Air (M4) and More Get Discounts During Vijay Sales Apple Days Sale
  3. Anthropic CEO Dario Amodei Says AI Models Hallucinate Less Than Humans: Report
  4. UK Government Updates Crypto Reporting Guidelines, Mandates Collection of Crypto Transaction Data
  5. Acer Swift Neo WIth Intel Core Ultra 5, Up to 32GB RAM Launched in India: Price, Specifications
  6. Elden Ring Film Adaptation in the Works at A24 With Alex Garland Set to Direct
  7. Noise Buds F1 TWS Earbuds With IPX5 Rating, Up to 50-Hour Total Playback Time Launched in India
  8. News Media Alliance Issues Statement on Google’s AI Mode, Calls It ‘Definition of Theft’
  9. Honor Pad 10 With Snapdragon 7 Gen 3 SoC, 10,100mAh Battery Launched: Price, Specifications
  10. Lava Bold N1, Lava Bold N1 Pro India Launch Teased; Pricing, Specifications Revealed
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.