
Google is facing some serious questions about the security of its applications after a researcher disclosed <A HREF="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1274261,00.html?track=sy160&asrc=RSS_RSS-10_160">a flaw in its popular Gmail offering.</A> The new issue is a variant of a cross-site scripting vulnerability in Gmail which could enable an attacker to silently forward emails and contacts from a remote user's account to any email account he chose.
The problem, discovered and detailed by GNUCitizen, a hacking group that tracks flaws in so-called Web 2.0 applications, arises when a user who is logged in to Gmail visits a malicious Web page with a special bit of code embedded in it. The page performs an action that injects a filter into the user's Gmail filter list.