For at least four months, YouTube was vulnerable to a sneaky exploit that could have leaked the email address of any of its users — all 2.7 billion of them.

Andisearch Writeup

A security researcher known as Brutecat discovered a vulnerability that could expose the email addresses of YouTube’s 2.7 billion users by exploiting two separate Google services[1][2]. The attack chain involved extracting Google Account identifiers (GaiaIDs) from YouTube’s block feature, then using Google’s Pixel Recorder app to convert these IDs into email addresses[1:1].

To prevent notification emails from alerting victims, Brutecat created recordings with 2.5 million character titles that broke the email notification system[1:2]. The exploit worked by intercepting server requests when clicking the three-dot menu in YouTube live chats, revealing users’ GaiaIDs without actually blocking them[2:1].

Brutecat reported the vulnerability to Google on September 15, 2024[1:3]. Google initially awarded $3,133, then increased the bounty to $10,633 after their product team reviewed the severity[1:4]. According to Google spokesperson Kimberly Samra, there was no evidence the vulnerability had been exploited by attackers[2:2].

Google patched both parts of the exploit on February 9, 2025, approximately 147 days after the initial disclosure[1:5].


  1. Brutecat - Leaking the email of any YouTube user for $10,000 ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  2. Forbes - YouTube Bug Could Have Exposed Emails Of 2.7 Billion Users ↩︎ ↩︎ ↩︎

Really glad I do not have a google account and avoid all of their services. 🙂

@Zerush@lemmy.ml
creator
link
fedilink
37d

Google even in this way logs your activity, because half of the internet, apps and services, apart of YT, use Google APIs, like google-taskmanager, googleanalytics, doubleclick.net and others, not only the Google services. Google permiys to manage and delete all this data, naturally it don’t say it and only few user know it, in the Google Dashboard. but only if you have an account. It’s a mess, but Google (Alphabet INC) is everywhere, you can’t avoid it completly, even avoiding its services, except using exclusively i2p or other descentralized apps and services. Google has had too many years a complete freedom to dominate the internet and ending its “don’t be evil”.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 124 users / day
  • 1.05K users / week
  • 1.3K users / month
  • 4.58K users / 6 months
  • 1 subscriber
  • 3.36K Posts
  • 85.4K Comments
  • Modlog