
A vulnerability in Google Photos, discovered by Imperva, a cybersecurity software company, allows hackers to track your location history and, along with it, anyone you've tagged in your photos.
Google in the latest version of the browser, Chrome 72, as well as on devices running Android 7.0 or later.
Imperva researcher Ron Masas first discovered a vulnerability in the web version of Google Photos that allowed malicious sites to expose where, when, and who you are with in your photos.
The problem lies in the way Google Photos works. The service uses metadata from a photo to provide information such as geographic location, date, and more. It also uses Google's artificial intelligence technology to detect objects in the photo and automatically tag people in the photo, information that users can use to conduct detailed searches if they wish.
In addition to users, however, malicious websites can also use this feature through browser-based attacks.
To do this, a user would have to click on a link to a malicious website while logged into Google Photos. A malicious link is sent via an instant message in a chat app or email, as well as via malicious Javascript via an ad.
Of course, this assumes that the user would have to open the malicious link, which is not very likely to happen.
This is not the first time Masas has detected such an attack.
He had previously discovered a side-channel attack on Facebook Messenger that would have allowed attackers to see the contacts with whom users had recently exchanged messages.
