Thursday, February 27, 2025
HomeGoogleGoogle Admits That Google Photos Sent Private Videos to Strangers And Allowed...

Google Admits That Google Photos Sent Private Videos to Strangers And Allowed to Download it

Published on

SIEM as a Service

Follow Us on Google News

Google admits that Google Photos were accidentally sent some of the user’s videos to strangers due to a “technical issue” between November 21st and November 25th.

Google Alerting users via Email notification that they have faced a technical issue in “Download your Data” service for Google Photos.

Download Your Data service that lets You export your backup data from the Google products you use, like your email, calendar, and photos. 

A technical privacy issue had been in the tool has led to exposing the stored videos in Google Photos to strangers who don’t own those videos.

In results, some of your videos might be visible to a random person who can even download the videos from the backup.

This Privacy issue affected the small number of Google Photo’s Users doesn’t provide any details on how many people were affected, nor the number of individual videos that were distributed to strangers.

According to Google ” less than 0.01% of Photos users attempting Takeouts were affected, and no other product was affected.”

According to Jon Oberheide , CTO Duo Security “To be clear, this is a big screw-up. I hope the number of affected parties is small, but the impact to those parties could be high…and very unsettling. But my real beef is with this nonchalant and non-specific notification email. Hopefully, Google follows up with more comms.”

Google ended a Statement with apologies and said ” We are notifying people about a bug that may have affected users who used Google Takeout to export their Google Photos content between November 21 and November 25. These users may have received either an incomplete archive, or videos—not photos—that were not theirs. We fixed the underlying issue and have conducted an in-depth analysis to help prevent this from ever happening again. We are very sorry this happened.” “

Google said that it was fixed this software bug and the technical issue has been identified and resolved.

Also Read: How Does World’s Highly Secured Google Network Works? Google’s Effort & Dedication

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

App with Over 100,000 Downloads from Google Play Steals User Data and Blackmails

A financial management app named Finance Simplified has been revealed as a malicious tool...

Google Issues Warning on Phishing Campaigns Targeting Higher Education Institutions

Google, in collaboration with its Mandiant Threat Intelligence team, has issued a warning about...

Android App on Google Play Targets Indian Users to Steal Login Credentials

A malicious Android application, Finance Simplified (package: com.someca.count), has been identified on the Google...