Webcams exposed in Google Drive clickjack attack
Attackers can access a user's Google Drive files and record them through their webcam by tricking the user into clicking hidden links, a researcher found.
The click-jacking attack takes advantage of the Google Picker application interface, which allows users to preview files stored within Drive and via third-party applications.
In a demonstration of the attack, researcher Tom Van Goethem (@tomvangoethem) showed users could be tricked into allowing an attacker to access private PDF files. The video showed how a clickjacking attack - crafted as a simple game requiring user mouse-clicks - could hide check boxes that, when clicked, granted access to Google Drive files. "... Google fails to verify whether a user is authorised to view the sensitive thumbnail," Van Goethem wrote in a post.