HomeSecuritySerious vulnerability in Google Drive Desktop for Windows

Serious vulnerability in Google Drive Desktop for Windows

A security vulnerability has been identified in the Google Drive Desktop app for Windows. It allows a logged-in user on a shared machine to gain full access to another user's Drive files without needing their credentials. The vulnerability results from a flawed access control mechanism in the way the app handles cached data.

vulnerability in Google Drive Desktop for Windows

The problem lies in the application's local caching system, known as DriveFS, which fails to properly isolate cached files between different user profiles on a Windows system.

According to Abdelghani Alhijawi, the Google Drive Desktop application stores synchronized files in a local directory (DriveFS). Due to improper isolation, an attacker can access the victim's cache folder, copy its contents, and replace their own DriveFS folder with the victim's data. Upon restarting the application, Google Drive loads the victim's entire drive, including "My Drive" and "Shared Drives," as if it belonged to the attacker, without requiring re-authentication.

See also: Warning: Serious vulnerabilities in NVIDIA NVDebug tool

Google Drive Desktop: Fundamental security principles affected:

– Zero Trust: The application mistakenly trusts the copied cache without verifying the user’s identity.
– Encryption at Rest: Cache files are not encrypted individually for each user, allowing them to be reused across different accounts.
– Identity Re-Entry: The application does not require a password or any form of re-entry when a different user’s cache is loaded.

This vulnerability presents a classic insider threat scenario, particularly dangerous in environments with shared workstations, such as offices, universities, or coworking spaces. An employee or any user on a shared system could secretly copy another person's Drive cache, gaining access to sensitive files such as contracts, financial records, HR documents, or source code.

The potential for data to be extracted, modified, or deleted is significant, posing risks of privacy breaches, failures to comply with regulations such as GDPR and HIPAA, and significant reputational damage. Insider threats are a well-known and costly problem, accounting for 22% of security breaches according to Verizon’s 2024 DBIR report.

See also: AsyncRAT exploits ConnectWise ScreenConnect

The vulnerability places the Google Drive Desktop application out of alignment with major global security standards such as NIST SP 800-53, ISO 27001, and SOC 2. These frameworks require strict data isolation, least-privileged access, Encryption at Rest , and strong session management. All of these are affected by the vulnerability in question.

The researcher who discovered the issue reported it to Google’s vulnerability program, but was told, “This is not considered a security flaw.” This response is concerning, as the flaw represents a failure to adhere to Zero Trust principles and leaves users exposed to significant risks.

Until Google addresses this issue, users and organizations are advised to take precautions:

– Avoid using Google Drive Desktop on shared computers. – Enforce strict permissions on separate Windows user profiles . – Use the application only on dedicated and managed endpoints to minimize insider threat risks.

Ultimately, the responsibility for the security of user data lies with the service provider. By failing to implement per-user encryption, require re-authentication for cached sessions, and adhere to Zero Trust principles, Google Drive Desktop currently falls short of basic security expectations.

See also: Critical vulnerability in Amp'ed RF BT-AP 111 Bluetooth Access Point

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The vulnerability in Google Drive Desktop shows how easily trust in essential productivity apps can be broken. Failure to isolate caches between users leaves data exposed to anyone sharing the same computer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS