PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Google Calendar Privacy Flaw Discovered

Posted on January 25, 2014 by pogowasright.org

Adnan Farooqui writes:

Terence Eden is a developer who has discovered a privacy flaw in Google Calendar. He found that Calendar will automatically invite anyone whose email is entered in the title of an entry, even if the user makes that entry in their private calendar and does not plan on inviting anyone else. Invitations are sent without notifying the user.

Read more on UberGizmo.  You can find Eden’s original blog post on his blog, here, where he provides this update:

Update 24 January: Google have agreed to fix this bug!

[W]e agree that the behavior you identified is undesirable, and we filed a bug with the Calendar team last week. They’ve been working on changing the behavior to make it clearer that someone has been added to the event in the situation you described.

While we won’t be getting any of the monetary reward from the bug bounty, Google have graciously decided to include us in their Security Hall of Fame.

Category: Breaches

Post navigation

← Constitutional Challenge to No Fly List Upheld
State Chiefs to Arne Duncan: We Won’t Share Student Data →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech

RSS Recent Posts on DataBreaches.net

  • Turkish Group Hacks Zero-Day Flaw to Spy on Kurdish Forces
  • Cyberattacks on Long Island Schools Highlight Growing Threat
  • Dior faces scrutiny, fine in Korea for insufficient data breach reporting; data of wealthy clients in China, South Korea stolen
  • Administrator Of Online Criminal Marketplace Extradited From Kosovo To The United States
  • Twilio denies breach following leak of alleged Steam 2FA codes
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy