A security researcher has discovered a simple but critical vulnerability in Google-owned YouTubethat could be exploited by anyone to bring down the popular video sharing website's entire business.
Kamil Hismatullin, a Russian security expert, found a simple logical vulnerability that allows him to delete any video from YouTube with a single click.
While searching for cross-site scripting (XSS) or Cross-Site Request Forgery (CSRF) bugs in YouTube Creator Studio, Hismatullin came across a simple logical bug that could eliminate any video by simply sending an ID number of any video in a post request.
The bug was simple but very critical, since it could be exploited by any attacker, with the aim of easily tricking YouTube into deleting any video from its system.
“I fought hard to get Bieber’s channel removed,” Hismatullin wrote in his blog post. “Luckily, none of Bieber’s videos were tampered with.”.
Referring to the consequences of the problem, Hismatullin said that “this vulnerability could create absolute destruction in a matter of minutes if it fell into the hands of attackers who could extort users’ content or simply disrupt YouTube by deleting a huge amount of videos in a very short period of time.”
The researcher reported the bug to Google, and the search engine giant fixed the error within a few hours. Hismatullin earned $5,000 as a reward from Google for finding and reporting this critical issue and an additional $1,337 as part of the company’s proactive vulnerability reporting payment system.
Over a month ago, a similar bug was reported in Facebook's systems, which could have been exploited by attackers to delete any photo from any Facebook account. However, the social networking giant has patched this relatively simple flaw.

