
A bug in Google Drive could be used by hackers to distribute malicious files, posing as legitimate documents or images. This allows attackers to carry out spear-phishing attacks with high success rates.
The problem lies in the “manage versions” feature, which is implemented in Google Drive and allows users to upload and manage different versions of a file.
The “manage versions” feature was designed to allow Google Drive users to update an older version of a file to a new one that has the same file extension. However, this does not appear to be the case.
Researcher A. Nikoci discovered that this feature allows users to upload a new version with any file extension, for any file stored in Google Drive, allowing the upload of malicious executables.
“Google allows you to change the file version without checking if it is the same file type,” Nikoci explained.
The researcher reported the issue to Google and shared his findings on TheHackerNews, where the following videos showing how the bug is exploited.
“As shown in the demo videos – which Nikoci shared exclusively with The Hacker News – in this way, a legitimate version of a file that has already been shared with a group of users can be replaced by a malicious file, which when online does not indicate new changes or display any warning, but when downloaded can be used to infect targeted systems,” a post on THN states.
A hacker could exploit the flaw to carry out spear-phishing attacks, using messages that include links to malicious files hosted on Google Drive. Using links to files stored on popular cloud storage systems is a well-known tactic used by many hackers to carry out successful attacks.
Experts pointed out thatGoogle Chrome appears to implicitly trust any file downloaded from Google Drive, even if it has been flagged as "malicious" by antivirus software.
Google recently addressed an email spoofing vulnerability affecting Gmail and G Suite. The vulnerability could be exploited by an attacker to send an email that appears to come from a Gmail or G Suite user. The message could bypass protection mechanisms such as Sender Policy Framework (SPF), DMARC, etc.
