A security vulnerability has been identified in the Google Drive Desktop app for Windows. It allows a logged-in user on a shared machine to gain full access to another user's Drive files without needing their credentials. The vulnerability results from a flawed access control mechanism in the way the app handles cached data.

The problem lies in the application's local caching system, known as DriveFS, which fails to properly isolate cached files between different user profiles on a Windows system.
According to Abdelghani Alhijawi, the Google Drive Desktop application stores synchronized files in a local directory (DriveFS). Due to improper isolation, an attacker can access the victim's cache folder, copy its contents, and replace their own DriveFS folder with the victim's data. Upon restarting the application, Google Drive loads the victim's entire drive, including "My Drive" and "Shared Drives," as if it belonged to the attacker, without requiring re-authentication.
See also: Warning: Serious vulnerabilities in NVIDIA NVDebug tool
Google Drive Desktop: Fundamental security principles affected:
– Zero Trust: The application mistakenly trusts the copied cache without verifying the user’s identity.
– Encryption at Rest: Cache files are not encrypted individually for each user, allowing them to be reused across different accounts.
– Identity Re-Entry: The application does not require a password or any form of re-entry when a different user’s cache is loaded.
This vulnerability presents a classic insider threat scenario, particularly dangerous in environments with shared workstations, such as offices, universities, or coworking spaces. An employee or any user on a shared system could secretly copy another person's Drive cache, gaining access to sensitive files such as contracts, financial records, HR documents, or source code.
The potential for data to be extracted, modified, or deleted is significant, posing risks of privacy breaches, failures to comply with regulations such as GDPR and HIPAA, and significant reputational damage. Insider threats are a well-known and costly problem, accounting for 22% of security breaches according to Verizon’s 2024 DBIR report.
See also: AsyncRAT exploits ConnectWise ScreenConnect
The vulnerability places the Google Drive Desktop application out of alignment with major global security standards such as NIST SP 800-53, ISO 27001, and SOC 2. These frameworks require strict data isolation, least-privileged access, Encryption at Rest , and strong session management. All of these are affected by the vulnerability in question.
The researcher who discovered the issue reported it to Google’s vulnerability program, but was told, “This is not considered a security flaw.” This response is concerning, as the flaw represents a failure to adhere to Zero Trust principles and leaves users exposed to significant risks.
Until Google addresses this issue, users and organizations are advised to take precautions:
– Avoid using Google Drive Desktop on shared computers. – Enforce strict permissions on separate Windows user profiles . – Use the application only on dedicated and managed endpoints to minimize insider threat risks.
Ultimately, the responsibility for the security of user data lies with the service provider. By failing to implement per-user encryption, require re-authentication for cached sessions, and adhere to Zero Trust principles, Google Drive Desktop currently falls short of basic security expectations.
See also: Critical vulnerability in Amp'ed RF BT-AP 111 Bluetooth Access Point
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The vulnerability in Google Drive Desktop shows how easily trust in essential productivity apps can be broken. Failure to isolate caches between users leaves data exposed to anyone sharing the same computer.
