Google Fixes Serious Security Bug Impacting Gmail, G Suite Users Months After Its Discovery

Google engineers fixed the bug within seven hours after it was ultimately made public.

Advertisement
By Jagmeet Singh | Updated: 21 August 2020 14:04 IST
Highlights
  • Google was informed about the bug on April 3
  • Security researcher Allison Husain made the bug public on Wednesday
  • Gmail and G Suite services were both vulnerable due to the bug

Gmail and G Suite users could be impacted by the bug that was discovered on April 1

Google has patched a security bug that was impacting both Gmail and G Suite email servers. The issue was identified and reported to Google in April, though the search giant took over four months in mitigation and ultimately released a patch on Wednesday. According to the security researcher who discovered the bug on April 1, it could have allowed hackers to send spoofed emails on behalf of any Gmail or G Suite users. The bug was also found to overcome Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting and Conformance (DMARC) rules while sending spoofed emails.

Security researcher Allison Husain publicly disclosed the bug impacting Gmail and G Suite email servers through a blog post on Wednesday that included a proof-of-concept (PoC). Husain said that although Google was planning to bring a fix sometime in September, it decided to patch the flaw within seven hours after it was made public. Google itself imposes a strict 90-day disclosure deadline for its bug-finding Project Zero initiative, publishing details about a bug at the end of the period regardless of whether the company has a fix for the issue — something Microsoft has learnt the hard way on several occasions.

Advertisement

As per Husain, the bug that was reported to Google on April 3 wasn't identical to the classic email spoofing that can easily be blocked by email servers using SPF and DMARC standards. “This issue is a bug unique to Google which allows an attacker to send mail as any other user or G Suite customer while still passing even the most restrictive SPF and DMARC rules,” said Husain.

The security researcher found that Google's backend structure for enabling Gmail and G Suite services could allow an attacker to redirect incoming emails and spoof the identity of any user using a native feature called “Change envelope recipient.” Husain also found that once exploited, the bug could send spoofed emails to an email gateway on Gmail and G Suite using custom mail routing rules and by overcoming the traditional SPF and DMARC checks.

Advertisement

“By chaining together both the broken recipient validation in G Suite's mail validation rules and an inbound gateway, I was able to cause Google's backend to resend mail for any domain which was clearly spoofed when it was received,” said Husain. “This is advantageous for an attacker if the victim they intend to impersonate also uses Gmail or G Suite because it means the message sent by Google's backend will pass both SPF and DMARC as their domain will, by nature of using G Suite, be configured to allow Google's backend to send mail from their domain.”

Husain added that since the spoofed emails were originating from Google's backend, they weren't likely to be caught by regular spam filters.

Advertisement

It is important to note that Google has deployed the patch at the server side, as noted by Catalin Cimpanu of ZDNet. Thus, users on Gmail and G Suite aren't required to make any changes from their end.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Gmail, G Suite, Google, email spoofing
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y600 Turbo Launched With 9,000mAh Battery at This Price
  2. Xiaomi 17T, Xiaomi 17 Pro Price, Storage Variants Leak Ahead of Launch
  3. Here's When the Motorola Edge 70 Pro+ Will Launch in India
  4. Epic Games Unveils Unreal Engine 6 Along With 'New Era' of Rocket League
  5. A New OnePlus Pad With This OLED Display Could Launch in India Soon
  6. Apple's iOS 27 Update May Arrive With a Revamped AirPods Settings Interface
  7. Apple's AI-Powered Health Coach Said to Face Delays Ahead of watchOS 27
  1. Samsung Galaxy Z Fold 8 Series Naming Scheme Leaked; Flagship Model Said to Arrive With ‘Ultra’ Branding
  2. Moto G37, Moto G37 Power Go on Sale in India Alongside Moto Buds 2: Price, Offers
  3. Bitcoin Recovers Above $77,300 as Easing Geopolitical Tensions Drive Crypto Market Recovery
  4. Apple Is Reportedly Working on a New Gen AI Website Ahead of WWDC 2026
  5. Apple to Introduce Improved Genmoji, Image Playground Upgrades With iOS 27 Update: Mark Gurman
  6. Apple's iOS 27 Update Said to Offer Revamped AirPods Settings Interface With Simplified Controls Layout
  7. Epic Games Unveils Unreal Engine 6 Along With 'New Era' of Rocket League
  8. Vivo S60 Geekbench Listing Reveals Key Specifications Including Snapdragon 8s Gen 3 Chip, 16GB RAM
  9. Who's Your Gynac? Season 2 Now Streaming Online: What You Need to Know
  10. OnePlus Pad Model With Compact OLED Display to Launch in India Soon, Tipster Claims
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.