New Delhi: Researchers have recently uncovered a cybersecurity threat that enables hackers to access individuals’ Google accounts without requiring their passwords. CloudSEK, a cybersecurity company, reported the discovery of a new type of malware actively tested by hacking groups, exploiting third-party cookies to gain unauthorised access to private data.
The exploit was initially identified in October 2023 when a hacker disclosed it on a Telegram channel. PRISMA, a developer, revealed a critical vulnerability allowing the generation of persistent Google cookies through token manipulation, providing continuous access to Google services even after a password reset, according to Pavan Karthick M, a threat intelligence researcher at CloudSEK.
The root of the exploit was traced back to an undocumented Google Oauth endpoint named “MultiLogin.” The hacker’s post detailed how accounts could be compromised due to a flaw in cookies, which are used by websites and browsers to track users and enhance efficiency.
Google authentication cookies typically allow users to access their accounts without repeated login entries. However, hackers found a way to retrieve these cookies, bypassing two-factor authentication. As per reports, the Chrome web browser is currently taking measures to restrict third-party cookies.
Google responded to the discovery, stating, “We routinely upgrade our defences against such techniques and to secure users who fall victim to malware. In this instance, Google has taken action to secure any compromised accounts detected.”
The tech giant recommended users regularly remove malware from their computers and activate Enhanced Safe Browsing in Chrome for protection against phishing and malware downloads. Pavan Karthick M emphasised the need for continuous monitoring of both technical vulnerabilities and human intelligence sources to stay ahead of emerging cyber threats.









































