Hey folks,
I wrote a technical breakdown of a vulnerability I discovered in Google Drive Desktop for Windows. It allows one user to copy the DriveFS cache from another user profile and gain full access to their Google Drive without any re-authentication.
The issue: Google Drive does not reverify the identity tied to the local DriveFS cache.
Anyone with local access can copy that cache and impersonate another Drive user. Violates basic Zero Trust and user isolation principles.
Google reviewed and responded that it is βnot a security vulnerability.β
I also discuss why this violates NIST, ISO 27001, SOC 2, and even GDPR/HIPAA compliance expectations.
π Full article here: π The Hidden Google Drive Flaw Nobody Talks About